What is CVE-2026-12800?
A SQL Injection vulnerability exists in the Premium Packages plugin for WordPress up to version 6.2.0 via the `code` parameter in the `/wp-json/wpdmpp/v1/cart/coupon` REST API endpoint due to insufficient escaping. Users are strongly advised to update the plugin to the latest version or disable the affected endpoint until a patch is applied.
Azərbaycanca: WordPress üçün Premium Packages plagininin 6.2.0 və əvvəlki versiyalarında REST API endpointində SQL Injection zəifliyi aşkarlanıb. Bu, `/wp-json/wpdmpp/v1/cart/coupon` sorğusunda `code` parametrinin düzgün işlənməməsi səbəbindən baş verir. İstifadəçilər plagini dərhal son versiyaya yeniləməli və ya müvəqqəti olaraq əlaqəli endpointi söndürməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
In which REST API endpoint does the CVE-2026-12800 vulnerability exist in the Premium Packages plugin for WordPress?
The vulnerability exists in the `/wp-json/wpdmpp/v1/cart/coupon` REST API endpoint due to insufficient escaping of the `code` parameter.
What should users do to protect the Premium Packages plugin from the SQL Injection vulnerability?
Users are strongly advised to update the plugin to the latest version or disable the affected endpoint until a patch is applied.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.