A vulnerability was found in codename065 Premium Packages Plugin up to 6.2.0 on WordPress and classified as critical. This affects the function
CouponCodes::find of the file /wp-json/wpdmpp/v1/cart/coupon of the component CouponCodes. The manipulation of the argument code results in sql injection.
This vulnerability is cataloged as CVE-2026-12800. The attack may be launched remotely. There is no exploit available.