Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m363-6834-c3r7

Опубликовано: 16 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.

The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.

EPSS

Процентиль: 12%
0.00212
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 месяца назад

The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.

EPSS

Процентиль: 12%
0.00212
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284