CVE-2026-61948

Shahjada · WPDM – Premium Packages

The WPDM Premium Packages WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 6.2.0 and prior, permitting remote database query execution.

Executive summary

The WPDM Premium Packages plugin is susceptible to an unauthenticated SQL injection, creating a critical path for attackers to compromise database security.

Vulnerability

The plugin fails to properly neutralize special elements in SQL commands (CWE-89), enabling unauthenticated attackers to perform malicious database operations.

Business impact

Successful exploitation allows an attacker to bypass authentication and manipulate or extract data from the database. A CVSS score of 9.3 underscores the critical severity, which could result in significant data breaches or unauthorized access to sensitive digital assets managed by the plugin.

Remediation

Immediate Action: Update the WPDM – Premium Packages plugin to version 7.0.0 or higher.

Proactive Monitoring: Analyze application server logs for anomalous database interactions and monitor for unexpected administrative account activity.

Compensating Controls: Utilize a WAF to inspect incoming traffic for SQL injection payloads, which can provide an interim layer of protection if patching is delayed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant security risk to the integrity of the WordPress site. Administrators must upgrade to version 7.0.0 immediately to remediate the flaw and prevent potential exploitation by malicious actors.