Paytium: Mollie payment forms & donations
Paytium creates Mollie-powered payment and donation forms for accepting payments through WordPress websites.
Paytium: Mollie payment forms & donations (paytium) is a WordPress plugin with 14 published CVE records in this archive. The latest tracked vulnerability was published Sep 24, 2026; the highest published CVSS base score is 9.8.
paytiumCVE-2026-18467: Paytium unsigned payment metadata overrides the new account role
An unauthenticated attacker submits a public [paytium] payment form and completes the resulting payment flow. Although 5.0.3 signed pt-paytium-user-data, the later pt_cf_checkout_meta() filter on pt_meta_values copies attacker-supplied pt_form_field keys without signature verification. A pt-user-role value can overwrite the signed builder output, persist as _pt-user-role, and reach wp_insert_user() through paytium_user_data_processing() as the new account role. This can create an administrator account; the attacker then uses the normal lost-password flow for their supplied email address. Form exposure and completion of the payment flow are required; a payment-free signup bypass is not established. Affected versions: <= 5.0.3. Confirmed fixed release: 5.0.4.
| Safe version |
|
||
|---|---|---|---|
| Sep 24, 2026 |
CVE-2026-18467
Paytium unsigned payment metadata overrides the new account role
An unauthenticated attacker submits a public [paytium] payment form and completes the resulting payment flow. Although 5.0.3 signed pt-paytium-user-data, the later pt_cf_checkout_meta() filter on pt_meta_values copies attacker-supplied pt_form_field keys without signature verification. A pt-user-role value can overwrite the signed builder output, persist as _pt-user-role, and reach wp_insert_user() through paytium_user_data_processing() as the new account role. This can create an administrator account; the attacker then uses the normal lost-password flow for their supplied email address. Form exposure and completion of the payment flow are required; a payment-free signup bypass is not established. Affected versions: <= 5.0.3. Confirmed fixed release: 5.0.4.
|
5.0.4 |
CVE9.8
NVDPending
|
| Jun 26, 2026 |
CVE-2026-56030
Paytium: Privilege escalation or authentication bypass
Paytium is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 5.0.2.
|
5.0.3 |
CVE9.8
NVDPending
|
| Jan 24, 2025 |
CVE-2025-24552
Paytium: A security weakness
Paytium is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 31, 2024 |
CVE-2024-51667
Paytium: A security weakness
Paytium is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 16, 2024 |
CVE-2023-7294
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.1
NVD6.5
|
| Oct 16, 2024 |
CVE-2023-7293
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Oct 16, 2024 |
CVE-2023-7292
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 16, 2024 |
CVE-2023-7291
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.1
NVD8.1
|
| Oct 16, 2024 |
CVE-2023-7290
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Oct 16, 2024 |
CVE-2023-7289
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD4.3
|
| Oct 16, 2024 |
CVE-2023-7288
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD4.3
|
| Oct 16, 2024 |
CVE-2023-7287
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Mar 13, 2024 |
CVE-2024-25099
Paytium: Mollie payment forms & donations: Cross-site scripting
Paytium: Mollie payment forms & donations is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Dec 26, 2022 |
CVE-2022-4042
Paytium: Mollie payment forms & donations: Cross-site scripting
Paytium: Mollie payment forms & donations is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|