VYPR

Pronamic Pay

by WordPress

CVEs (1)

  • CVE-2026-16635Aug 1, 2026
    risk 0.00cvss epss 0.00

    The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly…