CVE-2026-73190: WordPress WPDM – Premium Packages plugin <= 7.0.5 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPDM – Premium Packages pluginto a version that resolves this vulnerability.Fixed in 7.0.6
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Sites running WPDM – Premium Packages version 7.0.5 or earlier are affected according to the available data. The issue is remotely reachable and does not require attacker privileges, but exploitation requires user interaction.
What does an attacker need to exploit it?
An attacker does not need an account or other privileges to attempt exploitation. The CVSS vector indicates network access, low attack complexity, and required user interaction.
What is the potential impact of successful exploitation?
Successful exploitation can affect confidentiality, integrity, and availability at low impact levels, and the scope may extend beyond the vulnerable component. The vulnerability is classified as cross-site scripting.