Executive brief
Paytium is a WordPress plugin used to facilitate payments and donations on websites. A critical security flaw allows unauthorized individuals to gain administrative control over the website without needing a password. This could lead to complete site takeover, theft of customer data, or the injection of malicious content.
Technical details
A privilege escalation vulnerability exists in the Paytium plugin for WordPress (versions 5.0.2 and below) due to incorrect privilege assignment (CWE-266). The flaw allows an unauthenticated remote attacker to escalate their privileges, potentially gaining full administrative access to the WordPress environment. The vulnerability is exploitable over the network without user interaction. A fix is available in version 5.0.3.
Affected products
- paytiumsupport Paytium <= 5.0.2
Timeline
- 2026-06-06: disclosed: Reported by Nabil Irawan
- 2026-06-23: advisory: Patchstack advisory published
- 2026-06-26: advisory: NVD published date
- 2026-06-23: patched: Version 5.0.3 released to address the issue