CVE-2026-18467
Published 24 September 2026 · tracked since 25 September 2026
Description
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 patch introduced a wp_hash()/hash_equals() signature gate on the pt-paytium-user-data field, but left a second filter — pt_cf_checkout_meta(
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-100876 MEDIUM 6.3
- CVE-2026-100875 HIGH 7.3
- CVE-2026-100873 MEDIUM 4.3
- CVE-2026-100874 HIGH 7.3
- CVE-2026-101060 HIGH 8.2
- CVE-2026-101061 MEDIUM 4.7
- CVE-2026-101047 MEDIUM 5.3
- CVE-2026-101057 LOW 3.1
- CVE-2026-101058 MEDIUM 6.9
- CVE-2026-101044 HIGH 7.1