{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/wpdmpp/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-12800"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Premium Packages – Sell Digital Products Securely (\u003c 6.2.1)"],"_cs_severities":["high"],"_cs_tags":["wordpress","sql-injection","web-application","unauthenticated"],"_cs_type":"advisory","_cs_vendors":["WPDMPP"],"content_html":"\u003cp\u003eA critical SQL Injection vulnerability, tracked as CVE-2026-12800, has been identified in the Premium Packages - Sell Digital Products Securely plugin for WordPress, affecting all versions up to and including 6.2.0. This flaw resides within the \u003ccode\u003eCouponCodes::find()\u003c/code\u003e method, specifically impacting the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint. The vulnerability stems from insufficient input escaping, where user-supplied data is directly interpolated into a raw SQL query string without proper sanitization, such as using \u003ccode\u003e$wpdb-\u0026gt;prepare()\u003c/code\u003e or \u003ccode\u003eesc_sql()\u003c/code\u003e. This design weakness enables unauthenticated attackers to inject arbitrary SQL queries, thereby extending existing database operations. Successful exploitation can lead to unauthorized access and exfiltration of sensitive information stored within the WordPress database, posing a significant risk to data confidentiality and integrity.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a WordPress site running the Premium Packages - Sell Digital Products Securely plugin version 6.2.0 or earlier.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP POST request targeting the \u003ccode\u003e/wp-json/wpdmpp/v1/cart/coupon\u003c/code\u003e REST API endpoint.\u003c/li\u003e\n\u003cli\u003eThe request includes a specially crafted 'code' parameter containing SQL injection payloads (e.g., \u003ccode\u003e' OR 1=1 --\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe vulnerable plugin processes the 'code' parameter without proper escaping or sanitization.\u003c/li\u003e\n\u003cli\u003eThe malicious input is directly concatenated into a raw SQL query within the \u003ccode\u003eCouponCodes::find()\u003c/code\u003e method.\u003c/li\u003e\n\u003cli\u003eThe database executes the modified SQL query, allowing the attacker to bypass authentication, retrieve arbitrary data, or potentially manipulate database content.\u003c/li\u003e\n\u003cli\u003eThe attacker extracts sensitive information such as user credentials, order details, or other proprietary data from the database.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-12800 allows unauthenticated attackers to perform arbitrary SQL queries against the WordPress database. This can lead to the full compromise of sensitive data, including but not limited to user accounts, session tokens, personal identifiable information (PII), and payment-related details if stored in the database. The exfiltration of such data can result in significant financial losses, reputational damage, regulatory penalties, and further attacks leveraging compromised credentials. The broad installation base of WordPress plugins implies a wide potential victim scope for organizations utilizing this plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-12800 immediately by updating the Premium Packages - Sell Digital Products Securely plugin to version 6.2.1 or newer.\u003c/li\u003e\n\u003cli\u003eDeploy the \u003ccode\u003eDetect CVE-2026-12800 Exploitation - WordPress Premium Packages Plugin SQLi\u003c/code\u003e Sigma rule to your SIEM for early detection of exploitation attempts.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive web server logging for the \u003ccode\u003ewebserver\u003c/code\u003e category, including full request URI and query parameters, to ensure the detection rule can be fully utilized.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T09:18:40Z","date_published":"2026-07-28T09:18:40Z","id":"https://feed.craftedsignal.io/briefs/2026-07-premium-packages-wordpress-sqli/","summary":"The Premium Packages - Sell Digital Products Securely plugin for WordPress, in versions up to and including 6.2.0, is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint, allowing unauthenticated attackers to append additional SQL queries to extract sensitive database information.","title":"WordPress Premium Packages Plugin SQL Injection Vulnerability (CVE-2026-12800)","url":"https://feed.craftedsignal.io/briefs/2026-07-premium-packages-wordpress-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - WPDMPP","version":"https://jsonfeed.org/version/1.1"}