THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-16635 (HIGH 8.8) — The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly i

[NVD] CVE-2026-16635 (HIGH 8.8) — The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly i

mednvdPublished 2026-08-01

CVE-2026-16635 CVSS: 8.8 HIGH Published: 2026-08-01T09:17:00.970

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly into `WP_User::set_role()` without any allowlist valida

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16635