← WordPress Vulnerabilities
WordPress security by component

Pronamic Pay

Pronamic Pay is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; the highest published CVSS base score is 8.8.

Plugin slug: pronamic-ideal

CVE-2026-16635: Pronamic Pay role fields let Subscribers become Administrators

Pronamic Pay through 10.1.0 passes an attacker-controlled Gravity Forms value from the configured user-role field directly to maybe_update_user_role() and WP_User::set_role() without a role allowlist or capability comparison. When a Pronamic Pay feed has Update User Role enabled and mapped to that field, a Subscriber can submit administrator and elevate their own account.

PublishedAug 01, 2026
Known safe version10.2.0
Safe version
Aug 01, 2026 CVE-2026-16635
Pronamic Pay role fields let Subscribers become Administrators
Pronamic Pay through 10.1.0 passes an attacker-controlled Gravity Forms value from the configured user-role field directly to maybe_update_user_role() and WP_User::set_role() without a role allowlist or capability comparison. When a Pronamic Pay feed has Update User Role enabled and mapped to that field, a Subscriber can submit administrator and elevate their own account.
10.2.0
CVE8.8
NVDPending