CVE-2026-12800

Premium Packages <= 6.2.0 - Unauthenticated SQL Injection

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint in versions up to, and including, 6.2.0. This is due to insufficient escaping on the user-supplied parameter, which is interpolated directly into a raw SQL query string in the CouponCodes::find() method without use of $wpdb->prepare() or esc_sql(). This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.


We have discovered 288 live websites that are affected by CVE-2026-12800.

Run a Free Instant Scan




Affected Software

Product  Wpdm Premium Packages
Category Wordpress Plugins
Vulnerable Domains288 live websites (90% of Wpdm Premium Packages install base)
Vulnerable Versions
  • from 0 through 6.2
Vulnerable Versions Count1 versions ( 50% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jul 28, 2026
  • Updated - Jul 28, 2026

Credits

  • Talal Nasraddeen (finder)

Website Distribution by Country

Number of websites using CVE-2026-12800
United States93 websites



Germany29 websites
Japan29 websites
Italy24 websites
GB13 websites
France10 websites
Netherlands9 websites
Australia6 websites
Brazil6 websites
Spain6 websites

Website Distribution by TLD

Number of websites using CVE-2026-12800
.com127 websites
.org22 websites
.de19 websites
.it17 websites
.net8 websites
.jp7 websites
.nl6 websites
.ch5 websites
.co.uk5 websites
.pl5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-12800

Top websites that are affected by CVE-2026-12800. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com Japan***,***
*********.**.kr Korea, South*,***,***
************.com United States*,***,***
*******.***.br Brazil*,***,***
**************.org Italy*,***,***
**********.***.au Australia**,***,***
***************.com United States**,***,***
*************.**.uk GB**,***,***
***********.it Italy**,***,***
**********.com Germany**,***,***
See full domain list

FAQ

CVE-2026-12800 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Wpdm Premium Packages
A total of 288 websites have been identified as vulnerable to CVE-2026-12800, based on global website indexing conducted by WebTechSurvey.
The Wpdm Premium Packages is affected by the CVE-2026-12800 vulnerability.
Wpdm Premium Packages versions up to and including 6.2 are vulnerable to CVE-2026-12800.