PT-2026-97646 · WordPress · The Paytium: Mollie Payment Forms & Donations

·

CVE-2026-18467

·

Published

2026-09-24

·

Updated

2026-09-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Paytium: Mollie payment forms & donations plugin for WordPress versions prior to 5.0.4
Description A privilege escalation issue exists where unauthenticated attackers can register a new WordPress account with administrator privileges. The flaw occurs because the pt cf checkout meta() function, registered on the pt meta values hook, copies $ POST['pt form field'][*] keys into the payment meta array without signature verification. This allows the pt-user-role value to overwrite signed data, which is then processed by the paytium user data processing() function and passed as the role argument to wp insert user(). Exploitation requires submitting a payment via a publicly-exposed [paytium] shortcode form and completing the payment flow.
Recommendations Update the plugin to version 5.0.4 or later.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18467

Affected Products

The Paytium: Mollie Payment Forms & Donations