THREAT OPS › Threat News › [NVD] CVE-2026-16635 (HIGH 8.8) — The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly i
[NVD] CVE-2026-16635 (HIGH 8.8) — The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly i
CVE-2026-16635 CVSS: 8.8 HIGH Published: 2026-08-01T09:17:00.970
The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly into `WP_User::set_role()` without any allowlist valida
Indicators of compromise
- CVE-2026-16635cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16635