CVE-2026-16635 | Pronamic Pay Plugin up to 10.1.0 on WordPress Role Assignment maybe_update_user_role user_role_field_id privileges management (EUVD-2026-51795)
A vulnerability was found in Pronamic Pay Plugin up to 10.1.0 on WordPress. It has been rated as critical. Affected by this vulnerability is the function maybe_update_user_role of the component Role Assignment. This manipulation of the argument user_role_field_id causes improper privilege management.
This vulnerability is handled as CVE-2026-16635. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More