Sceawere

Vulnerability Detail

CVE-2026-19711UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Premium Packages Inadequate Balance Validation

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
Unknown
Product
Premium Packages
Attack Type
CWE-284 Improper Access Control
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-16T06:16:52.120Z",
  "pubdate": "2026-08-16T06:16:52.120Z",
  "executiveSummary": "The Premium Packages WordPress plugin before 7.0.7 suffers from an inadequate balance validation vulnerability affecting the withdrawal request mechanism. This flaw enables any authenticated user, regardless of their role or sales history, to submit a fraudulent payout request for an arbitrary monetary amount. The risk implications include potential financial loss for platform operators if an administrator inadvertently reviews and approves the illegitimate payout request. Exploitation of this vulnerability requires authenticated access to the target WordPress instance, such as a standard subscriber account with no prior sales generation. The attack mechanism exploits the application logic failure where server-side validation fails to cross-reference the requested payout amount against the requesting user's actual earned balance. No complex payloads or advanced execution techniques are necessary to initiate the request, as the vulnerability resides entirely in the absence of proper authorization and business logic verification during the withdrawal submission phase.",
  "technicalDetails": "The root cause of this vulnerability lies in a business logic flaw within the withdrawal request handling mechanism of the Premium Packages plugin before version 7.0.7. Specifically, the application fails to perform a server-side validation check to verify whether the amount specified in a withdrawal request corresponds to or remains within the bounds of the requesting user's actual earned balance.\nThe attack flow begins when an authenticated user with minimal privileges, such as a subscriber account possessing zero sales and no legitimate earnings, navigates to the withdrawal request interface. The user crafts an HTTP request submitting an arbitrary numerical value representing the desired payout amount. Due to the absence of proper input validation and balance verification routines within the vulnerable component, the application accepts the input and logs the withdrawal request into the system database without asserting the user's financial standing.\nOnce the fraudulent payout request is generated and queued within the administrative dashboard, the attack vector relies on social engineering or administrative oversight. An unsuspecting administrator reviewing pending payout requests observes the submitted arbitrary amount. Lacking contextual indicators within the interface that clearly denote the user's actual earnings versus the requested payout, the administrator may proceed to approve and execute the financial transfer, resulting in direct financial loss.\nThe vulnerable component is the withdrawal and payout processing module of the Premium Packages plugin. The affected versions encompass all iterations of the plugin released prior to version 7.0.7. The required privileges are minimal, necessitating only standard authentication as a baseline user role (e.g., subscriber). The network exposure is inherent to any standard WordPress deployment accessible via HTTP or HTTPS where user registration and authenticated sessions are permitted. Post-exploitation impact is characterized by unauthorized financial disbursement, fraudulent asset extraction, and potential compromise of merchant or platform liquidity if automated approval mechanisms are utilized or if administrators systematically fail to cross-reference requests with actual ledger histories."
}
CVE-2026-19711: Premium Packages Inadequate Balance Validation (MEDIUM Severity, CVSS: 6.5) - Sceawere