Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-18467— Paytium: Mollie payment forms & donations <= 5.0.3 - Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' Parameter

Quick assessment

Affected
paytiumsupport Paytium: Mollie payment forms & donations
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件 Paytium: Mollie payment forms & donations 在所有 5.0.3 及以下版本中存在权限提升漏洞。在 5.0.3 补丁中,开发人员为 字段引入了 / 签名验证机制,但遗漏了另一个过滤器函数 。该函数注册在 钩子上,且在已签名的构建逻辑之后执行,它未经验证签名就将 的所有键值原样复制到支付元数据数组中。 攻击者可以利用这一点,通过提交未经验证的 值来覆盖已签名路径中的输出。随后, 函数会读取持久化的 文章元数据,并将其直接作为角色参数传递给 函数。这使得未

CVSS 9.8 · Critical EPSS 0.39% · P31

Possible ATT&CK Techniques 1 AI

T1098.001 · Additional Cloud Credentials

Affected Version Matrix 1

VendorProduct Version RangeStatus
paytiumsupport Paytium: Mollie payment forms & donations ≤ 5.0.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18467

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Paytium: Mollie payment forms & donations <= 5.0.3 - Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equals() signature gate on the pt-paytium-user-data field, but left a second filter — pt_cf_checkout_meta(), registered on the pt_meta_values hook after the signed builder — that copies every $_POST['pt_form_field'][*] key verbatim into the payment meta array without any signature verification; this allows the pt-user-role value it copies to overwrite the signed path's output, after which paytium_user_data_processing() reads the persisted _pt-user-role post meta and passes it directly as the role argument to wp_insert_user(). This makes it possible for unauthenticated attackers to register a new WordPress account with the administrator role and fully take over the site. Exploitation requires submitting a payment through a publicly-exposed [paytium] shortcode form and completing the resulting payment flow, after which the attacker can seize the new administrator account via the standard lost-password flow on their supplied email address.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
paytiumsupport Paytium: Mollie payment forms & donations 0 ~ 5.0.3 -

II. Public POCs for CVE-2026-18467

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18467

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-18467 (1)

Other References for CVE-2026-18467 (1)

Other References for CVE-2026-18467 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-18467

No comments yet


Leave a comment