VYPR

Premium Packages - Sell Digital Products Securely

by WordPress

Source repositories

CVEs (7)

  • CVE-2023-4293HigAug 12, 2023
    risk 0.50cvss 8.8epss 0.01

    The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' function. This makes it possible for authenticated attackers,…

  • CVE-2026-12800HigJul 28, 2026
    risk 0.42cvss 7.5epss 0.00

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint in versions up to, and including, 6.2.0. This is due to insufficient escaping on the…

  • CVE-2024-10164MedNov 21, 2024
    risk 0.35cvss 6.4epss 0.01

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdmpp_pay_link shortcode in all versions up to, and including, 5.9.3 due to insufficient input sanitization and output escaping on user…

  • CVE-2024-11225MedNov 22, 2024
    risk 0.33cvss 6.1epss 0.01

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.9.3. This makes it possible for…

  • CVE-2024-7386MedSep 25, 2024
    risk 0.28cvss 4.3epss 0.00

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. This is due to missing nonce validation on the addRefund() function. This makes it possible for unauthenticated…

  • CVE-2026-15906MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-15348MedJul 23, 2026
    risk 0.00cvss 6.3epss 0.00

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function — hooked to the unauthenticated WordPress `wp`…