PT-2024-38315 · WordPress · The Premium Packages – Sell Digital Products Securely
Jonas Benjamin Friedli
·
Published
2024-09-24
·
Updated
2025-07-10
·
CVE-2024-7386
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Premium Packages – Sell Digital Products Securely plugin for WordPress versions up to, and including, 5.9.1
Description
The issue is related to Cross-Site Request Forgery due to missing nonce validation on the
addRefund() and wpdmpp async request() functions. This allows unauthenticated attackers to perform actions, such as initiating refunds, via a forged request if they can trick a site administrator or shop manager into performing an action like clicking on a link.Recommendations
For versions up to, and including, 5.9.1, consider disabling the
addRefund() and wpdmpp async request() functions until a patch is available to prevent exploitation. Restrict access to sensitive areas of the site to minimize the risk of attackers tricking administrators into performing malicious actions.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Premium Packages – Sell Digital Products Securely