CVE-2026-18467: CWE-269 Improper Privilege Management in paytiumsupport Paytium: Mollie payment forms & donations
The Paytium: Mollie payment forms & donations WordPress plugin up to version 5.0.3 contains a privilege escalation vulnerability. An unauthenticated attacker can exploit this flaw by submitting a payment through a publicly exposed shortcode form and completing the payment flow. Due to improper privilege management, the attacker can register a new WordPress account with administrator privileges, effectively taking over the site. The vulnerability arises because a second filter copies POST data into payment meta without signature verification, allowing the attacker to overwrite the user role. This vulnerability has a critical severity with a CVSS score of 9.8.
AI Analysis
Technical Summary
CVE-2026-18467 is a privilege escalation vulnerability in the Paytium: Mollie payment forms & donations WordPress plugin affecting all versions up to and including 5.0.3. Although version 5.0.3 introduced a signature check on the pt-paytium-user-data field, a second filter (pt_cf_checkout_meta) registered later copies POSTed form fields into payment meta without signature verification. This allows an attacker to overwrite the pt-user-role meta value, which is then used as the role argument in wp_insert_user(), enabling creation of a new administrator account by an unauthenticated attacker. Exploitation requires submitting a payment through a publicly accessible paytium shortcode form and completing the payment process, after which the attacker can take over the new admin account via the lost-password flow.
Potential Impact
Successful exploitation allows unauthenticated attackers to create new WordPress accounts with administrator privileges, resulting in full site takeover. This compromises confidentiality, integrity, and availability of the affected WordPress site.
Mitigation Recommendations
A patch is available in version 5.0.3 that partially addresses the issue by adding a signature gate on the pt-paytium-user-data field. However, the vulnerability persists in version 5.0.3 due to a second filter lacking signature verification. Users should upgrade to a version later than 5.0.3 once available that fully addresses this issue. Until then, restrict access to publicly exposed paytium shortcode forms or disable the plugin to prevent exploitation. Monitor vendor advisories for official fixes.
CVE-2026-18467: CWE-269 Improper Privilege Management in paytiumsupport Paytium: Mollie payment forms & donations
Description
The Paytium: Mollie payment forms & donations WordPress plugin up to version 5.0.3 contains a privilege escalation vulnerability. An unauthenticated attacker can exploit this flaw by submitting a payment through a publicly exposed shortcode form and completing the payment flow. Due to improper privilege management, the attacker can register a new WordPress account with administrator privileges, effectively taking over the site. The vulnerability arises because a second filter copies POST data into payment meta without signature verification, allowing the attacker to overwrite the user role. This vulnerability has a critical severity with a CVSS score of 9.8.
CVSS v3.1
Score 9.8critical
Affected software
paytiumsupport
Paytium: Mollie payment forms & donations
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-18467 is a privilege escalation vulnerability in the Paytium: Mollie payment forms & donations WordPress plugin affecting all versions up to and including 5.0.3. Although version 5.0.3 introduced a signature check on the pt-paytium-user-data field, a second filter (pt_cf_checkout_meta) registered later copies POSTed form fields into payment meta without signature verification. This allows an attacker to overwrite the pt-user-role meta value, which is then used as the role argument in wp_insert_user(), enabling creation of a new administrator account by an unauthenticated attacker. Exploitation requires submitting a payment through a publicly accessible paytium shortcode form and completing the payment process, after which the attacker can take over the new admin account via the lost-password flow.
Potential Impact
Successful exploitation allows unauthenticated attackers to create new WordPress accounts with administrator privileges, resulting in full site takeover. This compromises confidentiality, integrity, and availability of the affected WordPress site.
Mitigation Recommendations
A patch is available in version 5.0.3 that partially addresses the issue by adding a signature gate on the pt-paytium-user-data field. However, the vulnerability persists in version 5.0.3 due to a second filter lacking signature verification. Users should upgrade to a version later than 5.0.3 once available that fully addresses this issue. Until then, restrict access to publicly exposed paytium shortcode forms or disable the plugin to prevent exploitation. Monitor vendor advisories for official fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-07-31T08:28:18.576Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab48378f7a7c54106b23c90
Added to database: 09/24/2026, 01:57:12 UTC
Last enriched: 09/24/2026, 01:57:45 UTC
Last updated: 09/24/2026, 04:07:18 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.