WordPress security by component
Pronamic Pay
Plugin description
Pronamic Pay is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; the highest published CVSS base score is 8.8.
Plugin slug:
pronamic-idealLatest vulnerability
CVE-2026-16635: Pronamic Pay role fields let Subscribers become Administrators
Pronamic Pay through 10.1.0 passes an attacker-controlled Gravity Forms value from the configured user-role field directly to maybe_update_user_role() and WP_User::set_role() without a role allowlist or capability comparison. When a Pronamic Pay feed has Update User Role enabled and mapped to that field, a Subscriber can submit administrator and elevate their own account.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-16635
Pronamic Pay role fields let Subscribers become Administrators
Pronamic Pay through 10.1.0 passes an attacker-controlled Gravity Forms value from the configured user-role field directly to maybe_update_user_role() and WP_User::set_role() without a role allowlist or capability comparison. When a Pronamic Pay feed has Update User Role enabled and mapped to that field, a Subscriber can submit administrator and elevate their own account.
|
10.2.0 |
CVE8.8
NVDPending
|