Privilege Escalation in Paytium Payment Forms & Donations Plugin for WordPress
CVE-2026-18467
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 September 2026
What is CVE-2026-18467?
The Paytium: Mollie payment forms & donations plugin for WordPress is susceptible to Privilege Escalation, affecting all versions up to and including 5.0.3. This vulnerability arises from a flaw in how user roles are handled during payment processing. Although a patch was introduced in version 5.0.3, it does not fully secure the process. An attacker, by submitting a payment through a compromised form, can manipulate form fields to escalate their privileges, allowing them to create a new WordPress account with an administrator role. This can lead to full site takeover, highlighting the need for immediate action to secure vulnerable WordPress installations.
Affected Version(s)
Paytium: Mollie payment forms & donations 0 <= 5.0.3