External risk intelligence

Paytium WordPress Plugin Privilege Escalation Allows Site Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-18467

The vulnerability exists in a WordPress payment plugin designed to process public-facing payment and donation forms. Because these forms are intended to be accessible to visitors on the public internet to facilitate transactions, the vulnerable input vector is commonly exposed.

Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability has been identified in the Paytium WordPress plugin, which handles payment forms and donations. This issue, if exploited, could allow an unauthenticated attacker to gain full administrative control of a WordPress site. The primary concern is to confirm if this specific plugin is in use and whether it is exposed to the internet.

  • Unauthenticated attackers can take over WordPress sites.
  • Confirms use of payment plugin and public exposure.
  • Assess plugin relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by submitting a payment through a publicly accessible form, then manipulating the data sent to the plugin. This allows them to assign an administrator role to their newly created account, effectively taking full control of the WordPress site.

  • Public form exposure required.
  • Manipulate POST data during payment.
  • Full site takeover via admin role.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to gain administrative control of a WordPress site by submitting a payment through a publicly accessible form. The attacker could then register a new administrator account and take over the site.

  • Full WordPress site access.
  • Via public payment form submission.
  • Complete site takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the Paytium plugin affects WordPress sites. The plugin owner or the website administrator is responsible for addressing this issue. The first practical step is to identify all WordPress sites using the Paytium plugin, confirm if the payment forms are publicly accessible, and then plan remediation based on the risk of site takeover.

  • Plugin owner or website administrator owns this.
  • Verify public payment form exposure.
  • Plan remediation based on site risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Paytium: Mollie payment forms & donations plugin?

Paytium is a WordPress extension designed to integrate Mollie payment services directly into site pages. It allows website owners to create custom payment and donation forms using shortcodes. Users rely on this plugin to collect payments or contributions from visitors without leaving the WordPress environment.

What does CWE-269 mean for CVE-2026-18467?

CWE-269 refers to Improper Privilege Management. In this specific vulnerability, the plugin fails to properly restrict the user roles that can be assigned during account creation. By manipulating data sent during a transaction, an attacker can bypass authorization checks to grant themselves elevated administrative permissions.

How is this vulnerability triggered?

The flaw is triggered when an attacker submits data through an active payment form. By injecting specific values into the form fields, they can overwrite the user role settings during processing. Simply visiting a page with the plugin installed does not trigger the bug; the attacker must complete the payment submission flow.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a high-relevance issue because the plugin is designed for public-facing forms. If your payment forms are accessible to visitors on the internet to facilitate transactions, your site has the necessary exposure to be reached by an attacker.

What should I do if I use this plugin?

Your first step is to inventory all WordPress sites you manage to confirm if the Paytium plugin is active. Once identified, verify if any payment forms are currently exposed to the public. Prioritize these sites for immediate review and apply available updates from the developer to secure your administrative access.

References