The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function — hooked to the unauthenticated WordPress `wp` action — decoding the attacker-controlled `wpdmppdl` parameter using only `base64_decode()` and `json_decode()` with no HMAC, cryptographic signature, or nonce verification, and then issuing WordPress authentication cookies after a domain check that is trivially bypassed because both sides of the comparison are attacker-supplied values. This makes it possible for unauthenticated attackers to authenticate as any non-administrator WordPress user, including subscribers, customers, contributors, authors, editors, and shop managers, who owns an order, gaining full session-level access to that account.
We have discovered 322 live websites that are affected by CVE-2026-15348.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 322 live websites (100% of Wpdm Premium Packages install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 2 versions ( 100% of all versions) |
| 106 websites | |
| 35 websites | |
| 30 websites | |
| 25 websites | |
| 14 websites | |
| 12 websites | |
| 10 websites | |
| 10 websites | |
| 7 websites | |
| 6 websites |
| .com | 144 websites |
| .org | 25 websites |
| .de | 23 websites |
| .it | 17 websites |
| .net | 9 websites |
| .jp | 7 websites |
| .ch | 6 websites |
| .co.uk | 6 websites |
| .nl | 6 websites |
| .fr | 6 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****************.com | **,*** | ||
| ***********.com | ***,*** | ||
| *****.***.tr | ***,*** | ||
| ********.com | ***,*** | ||
| ***************.com | *,***,*** | ||
| ***********.com | *,***,*** | ||
| *********.de | *,***,*** | ||
| *********.**.kr | *,***,*** | ||
| **********.**.uk | *,***,*** | ||
| *********.net | *,***,*** |
FAQ