{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/pronamic-pay--10.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-16635"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Pronamic Pay (\u003c= 10.1.0)"],"_cs_severities":["high"],"_cs_tags":["wordpress","privilege-escalation","web-application"],"_cs_type":"advisory","_cs_vendors":["Pronamic"],"content_html":"\u003cp\u003eThe Pronamic Pay plugin for WordPress, in versions up to and including 10.1.0, contains a critical privilege escalation vulnerability identified as CVE-2026-16635. The flaw resides within the \u003ccode\u003emaybe_update_user_role()\u003c/code\u003e function, which processes data from Gravity Forms payment feeds. Specifically, the plugin takes user-controlled input from a Gravity Forms field and passes it directly to the \u003ccode\u003eWP_User::set_role()\u003c/code\u003e WordPress core function without performing any server-side validation, role allowlisting, or capability checks.\u003c/p\u003e\n\u003cp\u003eFor exploitation to occur, an administrator must have previously configured a Pronamic Pay payment feed with the 'Update User Role' feature enabled and mapped to a specific form field. An attacker with a low-privileged account, such as a Subscriber, can then submit a crafted request via the associated Gravity Forms instance, manipulating the mapped field value to set their own account role to 'Administrator'. Because the plugin performs no permission verification before calling the role update, this allows for immediate privilege escalation, granting the attacker full administrative control over the WordPress site.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated user to gain Administrator privileges on the affected WordPress site. This results in complete system compromise, enabling the attacker to install arbitrary plugins, modify site content, extract database information, or execute further malicious activities. The vulnerability impacts all WordPress installations utilizing Pronamic Pay up to version 10.1.0, posing a significant risk to organizations relying on this plugin for payment processing and user management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Pronamic Pay plugin to the latest version immediately to remediate CVE-2026-16635.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user accounts for unauthorized changes in administrative roles.\u003c/li\u003e\n\u003cli\u003eReview all Gravity Forms payment feed configurations to ensure the 'Update User Role' feature is disabled if not strictly required for business operations.\u003c/li\u003e\n\u003cli\u003eMonitor WordPress logs for unusual 'profile_update' or 'user_role_updated' actions associated with low-privileged user accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-01T09:50:20Z","date_published":"2026-08-01T09:50:20Z","id":"https://feed.craftedsignal.io/briefs/2026-08-pronamic-privilege-escalation/","summary":"The Pronamic Pay plugin for WordPress is vulnerable to privilege escalation via the unvalidated update of user roles in the Gravity Forms integration.","title":"Privilege Escalation in Pronamic Pay WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-pronamic-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Pronamic Pay (\u003c= 10.1.0)","version":"https://jsonfeed.org/version/1.1"}