CVE-2026-19711

Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount Withdrawal Request

The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.


We have discovered 293 live websites that are affected by CVE-2026-19711.

Run a Free Instant Scan




Affected Software

Product  Wpdm Premium Packages
Category Wordpress Plugins
Vulnerable Domains293 live websites (100% of Wpdm Premium Packages install base)
Vulnerable Versions
  • from 0 through 7.0.7
Vulnerable Versions Count4 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-284 Improper Access Control



Details

  • Published - Aug 16, 2026
  • Updated - Aug 17, 2026

Credits

  • Farid Narimanov (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-19711
United States105 websites



Germany38 websites
Japan18 websites
Italy16 websites
France14 websites
GB13 websites
Spain8 websites
Poland8 websites
Australia6 websites
Denmark6 websites

Website Distribution by TLD

Number of websites using CVE-2026-19711
.com138 websites
.org26 websites
.de23 websites
.it9 websites
.net8 websites
.fr7 websites
.pl7 websites
.co.uk6 websites
.ch4 websites
.nl4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-19711

Top websites that are affected by CVE-2026-19711. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.com United States**,***
*****.int United States***,***
***********.com United States***,***
*****.***.tr Turkey***,***
*****************************.de Germany***,***
***********.org France***,***
********************.org United States***,***
************.com United States***,***
*************.org United States***,***
*****************.com GB***,***
See full domain list

FAQ

CVE-2026-19711 is Improper Access Control in Wpdm Premium Packages
A total of 293 websites have been identified as vulnerable to CVE-2026-19711, based on global website indexing conducted by WebTechSurvey.
The Wpdm Premium Packages is affected by the CVE-2026-19711 vulnerability.
Wpdm Premium Packages versions up to 7.0.7 are vulnerable to CVE-2026-19711.
CVE-2026-19711 is resolved in version 7.0.7 of Wpdm Premium Packages.