Skip to main content
Vulnerability Database/CVE-2026-18467

CVE-2026-18467: Paytium Plugin Privilege Escalation Flaw

CVE-2026-18467 is a privilege escalation vulnerability in the Paytium WordPress plugin that lets unauthenticated attackers create administrator accounts. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-18467 Overview

CVE-2026-18467 is a privilege escalation vulnerability in the Paytium: Mollie payment forms & donations plugin for WordPress, affecting all versions up to and including 5.0.3. The flaw allows unauthenticated attackers to register a new WordPress account with the administrator role by submitting a payment through any publicly exposed [paytium] shortcode form. After completing the payment flow, the attacker uses the standard lost-password workflow on their supplied email address to seize the account and take over the site.

Critical Impact

Unauthenticated attackers can obtain administrator accounts on affected WordPress sites and achieve full site takeover through the standard payment submission flow.

Affected Products

  • Paytium: Mollie payment forms & donations plugin for WordPress
  • All versions up to and including 5.0.3
  • WordPress sites exposing [paytium] shortcode forms publicly

Discovery Timeline

  • 2026-09-24 - CVE-2026-18467 published to the National Vulnerability Database (NVD)
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-18467

Vulnerability Analysis

The root weakness is an incomplete authorization control classified under [CWE-269] Improper Privilege Management. The 5.0.3 release attempted to close a prior privilege escalation path by adding a wp_hash() and hash_equals() signature check on the pt-paytium-user-data field. However, the patch left a parallel code path that reintroduces the same abuse primitive.

A second filter, pt_cf_checkout_meta(), remains registered on the pt_meta_values hook after the signed builder runs. That filter copies every $_POST['pt_form_field'][*] key verbatim into the payment meta array with no signature verification. Because it executes later in the pipeline, the attacker-controlled pt-user-role value overwrites the signed path's output.

Downstream, paytium_user_data_processing() reads the persisted _pt-user-role post meta and passes it directly as the role argument to wp_insert_user(). The result is an attacker-defined role assignment during user creation.

Root Cause

The root cause is a trust boundary violation. The plugin enforces signature validation on one input path but permits an unauthenticated, parallel filter to overwrite the validated value before it reaches the user provisioning function. Signed data is treated as authoritative until an unsigned hook silently replaces it.

Attack Vector

Exploitation requires network access to any page hosting the [paytium] shortcode. The attacker submits the payment form with a crafted pt_form_field[pt-user-role] value set to administrator, completes the Mollie payment flow, and provides an email address they control. WordPress then creates the account with administrator privileges. The attacker triggers a password reset through the standard lost-password flow to gain interactive access.

See the Wordfence Vulnerability Analysis and the WordPress Paytium User Data Functions reference for the vulnerable code paths.

Detection Methods for CVE-2026-18467

Indicators of Compromise

  • New WordPress user accounts with the administrator role created shortly after a Paytium payment transaction completes.
  • Post meta entries named _pt-user-role containing values such as administrator, editor, or other elevated roles.
  • Successful wp_insert_user() events correlated with [paytium] shortcode form submissions from unauthenticated sessions.
  • Password reset requests immediately following account creation from a Paytium payment source.

Detection Strategies

  • Inspect HTTP request bodies to Paytium form endpoints for pt_form_field[pt-user-role] parameters containing privileged role values.
  • Audit the wp_users and wp_usermeta tables for accounts created by the plugin with wp_capabilities containing administrator.
  • Correlate WordPress user creation events with the completion of Mollie webhook callbacks handled by the Paytium plugin.

Monitoring Recommendations

  • Enable WordPress audit logging for user_register, set_user_role, and password_reset events.
  • Alert on any administrator account creation outside of expected administrative workflows.
  • Monitor web server logs for POST requests containing pt_form_field array parameters with role-related keys.

How to Mitigate CVE-2026-18467

Immediate Actions Required

  • Deactivate the Paytium plugin on any site running version 5.0.3 or earlier until a patched release is installed.
  • Remove or restrict access to any page containing the [paytium] shortcode from unauthenticated visitors.
  • Audit all administrator, editor, and author accounts and remove any created through the Paytium flow.
  • Rotate credentials and secrets for any WordPress account that may have been compromised.

Patch Information

Refer to the plugin repository for the fix following Changeset #3678569. Site administrators should upgrade to the version that removes or hardens the pt_cf_checkout_meta() filter on the pt_meta_values hook, ensuring the pt-user-role value cannot be overwritten by unsigned $_POST['pt_form_field'] input before reaching wp_insert_user().

Workarounds

  • Remove all [paytium] shortcode instances from publicly accessible pages until the patched version is deployed.
  • Use a Web Application Firewall (WAF) rule to block POST requests containing pt_form_field[pt-user-role] parameters.
  • Restrict the WordPress wp_insert_user() role assignment through a custom mu-plugin that forces the default subscriber role for Paytium-originated registrations.
  • Disable user registration site-wide in WordPress general settings if payment forms are not required for provisioning accounts.
bash
# Example WAF rule concept (ModSecurity) to block role parameter tampering
SecRule ARGS_NAMES "@rx pt_form_field\[pt-user-role\]" \
    "id:1026184670,phase:2,deny,status:403,log,\
    msg:'CVE-2026-18467 Paytium role parameter tampering attempt'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.