PatchSiren

pronamic CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH pronamic CVE published 2026-08-01

CVE-2026-16635

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0. This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value directly into `WP_User::set_role()` without any allowlist validation, capability comparison, or permission check to constrain which roles can be assigned. Authenticated attac [truncated]