Paytium unsigned payment metadata overrides the new account role
An unauthenticated attacker submits a public [paytium] payment form and completes the resulting payment flow. Although 5.0.3 signed pt-paytium-user-data, the later pt_cf_checkout_meta() filter on pt_meta_values copies attacker-supplied pt_form_field keys without signature verification. A pt-user-role value can overwrite the signed builder output, persist as _pt-user-role, and reach wp_insert_user() through paytium_user_data_processing() as the new account role. This can create an administrator account; the attacker then uses the normal lost-password flow for their supplied email address. Form exposure and completion of the payment flow are required; a payment-free signup bypass is not established. Affected versions: <= 5.0.3. Confirmed fixed release: 5.0.4.
- Component
- Paytium: Mollie payment forms & donations
- Plugin slug
paytium- Affected
- <= 5.0.3
- Safe version
5.0.4- Published
- Sep 24, 2026
This CVE was published Sep 24, 2026 and is one of 14 known issues for this plugin.
Update, patch or deactivate.
Update to 5.0.4 or later, preferably the current supported release. Derive account roles from trusted server-side configuration, reject reserved role keys from untrusted payment metadata, and enforce the same integrity checks on every builder and filter. Review payment-created administrator accounts and unexpected role-bearing payment metadata. The official changelog matches this fix in 5.0.4. Official changelog: https://wordpress.org/plugins/paytium/#developers
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equals() signature gate on the pt-paytium-user-data field, but left a second filter — pt_cf_checkout_meta(), registered on the pt_meta_values hook after the signed builder — that copies every $_POST['pt_form_field'][*] key verbatim into the payment meta array without any signature verification; this allows the pt-user-role value it copies to overwrite the signed path's output, after which paytium_user_data_processing() reads the persisted _pt-user-role post meta and passes it directly as the role argument to wp_insert_user(). This makes it possible for unauthenticated attackers to register a new WordPress account with the administrator role and fully take over the site. Exploitation requires submitting a payment through a publicly-exposed [paytium] shortcode form and completing the resulting payment flow, after which the attacker can seize the new administrator account via the standard lost-password flow on their supplied email address.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Primary and upstream sources
- NVD record for CVE-2026-18467
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- WordPress upstream reference plugins.trac.wordpress.org
- Wordfence advisory wordfence.com