What is CVE-2026-15348?
The Premium Packages – Sell Digital Products Securely plugin for WordPress (all versions up to and including 7.0.4) is vulnerable to Authentication Bypass via the `wpdmppdl` parameter. This is due to the `download()` function, hooked to the unauthenticated WordPress `wp` action, improperly decoding the parameter. Immediately update the plugin to a patched version beyond 7.0.4.
Azərbaycanca: Premium Packages – Sell Digital Products Securely adlı WordPress plaqini (7.0.4 daxil olmaqla bütün versiyalar) `wpdmppdl` parametri vasitəsilə həssasdır. Bu zəiflik, autentifikasiya olunmamış `wp` aksiyasına bağlanan `download()` funksiyasının səhv kodlaşdırması səbəbindən yaranır və təcavüzkarlara autentifikasiyanı keçməyə imkan verir. Plaqini dərhal ən son təhlükəsizlik yamasını ehtiva edən versiyaya yeniləyin.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
How does the CVE-2026-15348 vulnerability bypass authentication in the Premium Packages plugin?
The vulnerability arises because the plugin's `download()` function, hooked to the unauthenticated `wp` action, improperly decodes the `wpdmppdl` parameter.
What version of the Premium Packages plugin is needed to protect against CVE-2026-15348?
You must immediately update the Premium Packages plugin to a version beyond 7.0.4 that contains the latest security patch.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.