CVE-2026-16635

WordPress · Pronamic Pay

The Pronamic Pay plugin for WordPress contains an improper privilege management vulnerability, allowing authenticated users to perform unauthorized actions.

Executive summary

A privilege escalation vulnerability in the Pronamic Pay WordPress plugin allows authenticated attackers to gain elevated access, posing a high risk to site integrity.

Vulnerability

This is a privilege escalation flaw caused by improper privilege management. It requires the attacker to have at least low-level authenticated access to the WordPress site to exploit the vulnerability.

Business impact

Successful exploitation of this vulnerability allows a low-privileged user to escalate their permissions, potentially gaining administrative control over the WordPress installation. With a CVSS score of 8.8, this represents a significant threat to confidentiality, integrity, and availability, as an attacker could modify site content, access sensitive payment data, or disrupt business operations.

Remediation

Immediate Action: Update the Pronamic Pay plugin to version 10.2.0 or later immediately to resolve the privilege management flaw.

Proactive Monitoring: Review WordPress user account logs for suspicious activity or unauthorized changes to user roles and capabilities.

Compensating Controls: Use a Web Application Firewall to monitor and block abnormal requests targeting plugin-specific functionality, though an update remains the only definitive fix.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the nature of privilege escalation, administrators must prioritize this update. Ensure that all WordPress plugins are kept up to date and that user roles are audited periodically to minimize the impact of such vulnerabilities.