← WordPress Vulnerabilities
WordPress security by component

Paytium: Mollie payment forms & donations

Paytium creates Mollie-powered payment and donation forms for accepting payments through WordPress websites.

Paytium: Mollie payment forms & donations (paytium) is a WordPress plugin with 14 published CVE records in this archive. The latest tracked vulnerability was published Sep 24, 2026; the highest published CVSS base score is 9.8.

Plugin slug: paytium

CVE-2026-18467: Paytium unsigned payment metadata overrides the new account role

An unauthenticated attacker submits a public [paytium] payment form and completes the resulting payment flow. Although 5.0.3 signed pt-paytium-user-data, the later pt_cf_checkout_meta() filter on pt_meta_values copies attacker-supplied pt_form_field keys without signature verification. A pt-user-role value can overwrite the signed builder output, persist as _pt-user-role, and reach wp_insert_user() through paytium_user_data_processing() as the new account role. This can create an administrator account; the attacker then uses the normal lost-password flow for their supplied email address. Form exposure and completion of the payment flow are required; a payment-free signup bypass is not established. Affected versions: <= 5.0.3. Confirmed fixed release: 5.0.4.

PublishedSep 24, 2026
Known safe version5.0.4
Published vulnerabilities for paytium
Safe version
Sep 24, 2026 CVE-2026-18467
Paytium unsigned payment metadata overrides the new account role
An unauthenticated attacker submits a public [paytium] payment form and completes the resulting payment flow. Although 5.0.3 signed pt-paytium-user-data, the later pt_cf_checkout_meta() filter on pt_meta_values copies attacker-supplied pt_form_field keys without signature verification. A pt-user-role value can overwrite the signed builder output, persist as _pt-user-role, and reach wp_insert_user() through paytium_user_data_processing() as the new account role. This can create an administrator account; the attacker then uses the normal lost-password flow for their supplied email address. Form exposure and completion of the payment flow are required; a payment-free signup bypass is not established. Affected versions: <= 5.0.3. Confirmed fixed release: 5.0.4.
5.0.4
CVE9.8
NVDPending
Jun 26, 2026 CVE-2026-56030
Paytium: Privilege escalation or authentication bypass
Paytium is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 5.0.2.
5.0.3
CVE9.8
NVDPending
Jan 24, 2025 CVE-2025-24552
Paytium: A security weakness
Paytium is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 31, 2024 CVE-2024-51667
Paytium: A security weakness
Paytium is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Oct 16, 2024 CVE-2023-7294
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.1
NVD6.5
Oct 16, 2024 CVE-2023-7293
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Oct 16, 2024 CVE-2023-7292
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Oct 16, 2024 CVE-2023-7291
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.1
NVD8.1
Oct 16, 2024 CVE-2023-7290
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Oct 16, 2024 CVE-2023-7289
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Oct 16, 2024 CVE-2023-7288
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Oct 16, 2024 CVE-2023-7287
Paytium: Mollie payment forms & donations: A security weakness
Paytium: Mollie payment forms & donations is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
Mar 13, 2024 CVE-2024-25099
Paytium: Mollie payment forms & donations: Cross-site scripting
Paytium: Mollie payment forms & donations is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Dec 26, 2022 CVE-2022-4042
Paytium: Mollie payment forms & donations: Cross-site scripting
Paytium: Mollie payment forms & donations is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8