Skip to content

Menu
  • Home
Menu

CVE-2026-18467 – Paytium: Mollie payment forms & donations <= 5.0.3 – Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' Parameter

Posted on September 24, 2026
CVE ID :CVE-2026-18467

Published : Sept. 24, 2026, 1:27 a.m. | 34 minutes ago

Description :The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equals() signature gate on the pt-paytium-user-data field, but left a second filter — pt_cf_checkout_meta(), registered on the pt_meta_values hook after the signed builder — that copies every $_POST[‘pt_form_field’][*] key verbatim into the payment meta array without any signature verification; this allows the pt-user-role value it copies to overwrite the signed path’s output, after which paytium_user_data_processing() reads the persisted _pt-user-role post meta and passes it directly as the role argument to wp_insert_user(). This makes it possible for unauthenticated attackers to register a new WordPress account with the administrator role and fully take over the site. Exploitation requires submitting a payment through a publicly-exposed [paytium] shortcode form and completing the resulting payment flow, after which the attacker can seize the new administrator account via the standard lost-password flow on their supplied email address.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

🤖 AI-Generated Patch Solution

Google Gemini (gemini-2.5-flash) • CVE: CVE-2026-18467

Unknown
N/A
⚠️ Vulnerability Description:

1. IMMEDIATE ACTIONS

System Isolation: Immediately quarantine all affected AcmeAppServer instances from the network. This involves implementing temporary firewall rules to block all inbound and outbound network traffic except for essential management access from a secured jump box or administrative subnet.
Network Access Restriction: Implement temporary firewall rules to block external and untrusted network access to AcmeAppServer's RMI (default port 10

💡 AI-generated — review with a security professional before acting.View on NVD →
Post Views: 3

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme