CVE-2026-73190

WordPress WPDM – Premium Packages plugin <= 7.0.5 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.


We have discovered 293 live websites that are affected by CVE-2026-73190.

Run a Free Instant Scan




Affected Software

Product  Wpdm Premium Packages
Category Wordpress Plugins
Vulnerable Domains293 live websites (100% of Wpdm Premium Packages install base)
Vulnerable Versions
  • from 0 through 7.0.5
Vulnerable Versions Count4 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 18, 2026
  • Updated - Aug 18, 2026

Credits

  • Evan NR | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-73190
United States105 websites



Germany38 websites
Japan18 websites
Italy16 websites
France14 websites
GB13 websites
Spain8 websites
Poland8 websites
Australia6 websites
Denmark6 websites

Website Distribution by TLD

Number of websites using CVE-2026-73190
.com138 websites
.org26 websites
.de23 websites
.it9 websites
.net8 websites
.fr7 websites
.pl7 websites
.co.uk6 websites
.ch4 websites
.nl4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-73190

Top websites that are affected by CVE-2026-73190. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.com United States**,***
*****.int United States***,***
***********.com United States***,***
*****.***.tr Turkey***,***
*****************************.de Germany***,***
***********.org France***,***
********************.org United States***,***
************.com United States***,***
*************.org United States***,***
*****************.com GB***,***
See full domain list

FAQ

CVE-2026-73190 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Wpdm Premium Packages
A total of 293 websites have been identified as vulnerable to CVE-2026-73190, based on global website indexing conducted by WebTechSurvey.
The Wpdm Premium Packages is affected by the CVE-2026-73190 vulnerability.
Wpdm Premium Packages versions up to and including 7.0.5 are vulnerable to CVE-2026-73190.