PT-2026-67120 · WordPress+1 · Pronamic Pay+1
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pronamic Pay versions prior to 10.1.1
Description
The plugin is subject to privilege escalation. The
maybe update user role() function passes an attacker-controlled Gravity Forms field value ($lead[$feed->user role field id]) directly into WP User::set role() without allowlist validation, capability comparison, or permission checks. This allows authenticated users with Subscriber-level access or higher to escalate their account privileges to Administrator by tampering with the role field value during a form submission. This issue occurs when an administrator has configured a Pronamic Pay payment feed in Gravity Forms with the Update User Role option enabled and mapped to a form field.Recommendations
Update to a version newer than 10.1.0.
As a temporary mitigation, disable the Update User Role option in the Pronamic Pay payment feed configuration within Gravity Forms.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gravity Forms
Pronamic Pay