PT-2026-67120 · WordPress+1 · Pronamic Pay+1

·

CVE-2026-16635

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pronamic Pay versions prior to 10.1.1
Description The plugin is subject to privilege escalation. The maybe update user role() function passes an attacker-controlled Gravity Forms field value ($lead[$feed->user role field id]) directly into WP User::set role() without allowlist validation, capability comparison, or permission checks. This allows authenticated users with Subscriber-level access or higher to escalate their account privileges to Administrator by tampering with the role field value during a form submission. This issue occurs when an administrator has configured a Pronamic Pay payment feed in Gravity Forms with the Update User Role option enabled and mapped to a form field.
Recommendations Update to a version newer than 10.1.0. As a temporary mitigation, disable the Update User Role option in the Pronamic Pay payment feed configuration within Gravity Forms.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16635

Affected Products

Gravity Forms
Pronamic Pay