plugin

Paytium Vulnerabilities

37 known security issues reported for the Paytium WordPress plugin. Most recent disclosed Jun 23, 2026.

1 critical 2 high 11 medium

Running Paytium on your site? Check whether your installed version is affected.

Scan your site free

Paytium: Mollie payment forms & donations <= 5.0.2 - Unauthenticated Privilege Escalation

critical

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.2. This makes it possible for unauthenticated attackers to elevate their privileges.

CVSS:
9.8
Affected:
up to 5.0.2
Fixed in:
5.0.3
Disclosed:
Jun 23, 2026

CVE-2026-56030 on NVD →

Paytium <= 4.4.11 - Unauthenticated Full Path Disclosure

medium

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.4.11. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed...

CVSS:
5.3
Affected:
up to 4.4.11
Fixed in:
4.4.12
Disclosed:
Jan 24, 2025

CVE-2025-24552 on NVD →

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4.12

unknown

[en] Generation of Error Message Containing Sensitive Information vulnerability in David de Boer Paytium allows Retrieve Embedded Sensitive Data. This issue affects Paytium: from n/a through 4.4.11.

Affected:
up to 4.4.12
Fixed in:
4.4.12
Disclosed:
Jan 24, 2025

CVE-2025-24552 on NVD →

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4.11

unknown

[en] Missing Authorization vulnerability in David de Boer Paytium.This issue affects Paytium: from n/a through 4.4.10.

Affected:
up to 4.4.11
Fixed in:
4.4.11
Disclosed:
Dec 31, 2024

CVE-2024-51667 on NVD →

Paytium <= 4.4.10 - Missing Authorization

medium

The Paytium plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the paytium_emails_attachments() function in versions up to, and including, 4.4.10. This makes it possible for authenticated attackers, with subscriber-level access and above, to get attachment data.

CVSS:
4.3
Affected:
up to 4.4.10
Fixed in:
4.4.11
Disclosed:
Nov 1, 2024

CVE-2024-51667 on NVD →

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to crea...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Oct 16, 2024

CVE-2023-7294 on NVD →

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the paytium_sw_save_api_keys function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to chan...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Oct 16, 2024

CVE-2023-7289 on NVD →

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Oct 16, 2024

CVE-2023-7288 on NVD →

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal due to a missing capability check on the paytium_notice_dismiss function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access t...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Oct 16, 2024

CVE-2023-7292 on NVD →

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_mollie_account_details function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Oct 16, 2024

CVE-2023-7293 on NVD →

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_mollie_account function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to s...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Oct 16, 2024

CVE-2023-7291 on NVD →

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_for_verified_profiles function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to c...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Oct 16, 2024

CVE-2023-7290 on NVD →

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the pt_cancel_subscription function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level acces...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Oct 16, 2024

CVE-2023-7287 on NVD →

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David de Boer Paytium: Mollie payment forms & donations allows Stored XSS.This issue affects Paytium: Mollie payment forms & donations: from n/a through 4.4.2.

Affected:
up to 4.4.3
Fixed in:
4.4.3
Disclosed:
Mar 13, 2024

CVE-2024-25099 on NVD →

Paytium: Mollie payment forms & donations <= 4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

medium

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac...

CVSS:
6.4
Affected:
up to 4.4.2
Fixed in:
4.4.3
Disclosed:
Feb 12, 2024

CVE-2024-25099 on NVD →

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

Update the WordPress Paytium: Mollie payment forms & donations plugin to the latest available version (at least 4.4). Unknown discovered and reported this Broken Access Control vulnerability in WordPress Paytium: Mollie payment forms & donations Plugin. This vulnerability has been fixed in version 4.4.

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Mar 8, 2023

Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'create_mollie_account'

high

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_mollie_account function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to set up...

CVSS:
7.1
Affected:
up to 4.3.7
Fixed in:
4.4
Disclosed:
Mar 6, 2023

CVE-2023-7291 on NVD →

Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'create_mollie_profile'

high

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to create a...

CVSS:
7.1
Affected:
up to 4.3.7
Fixed in:
4.4
Disclosed:
Mar 6, 2023

CVE-2023-7294 on NVD →

Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'paytium_sw_save_api_keys'

medium

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the paytium_sw_save_api_keys function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to change pl...

CVSS:
5.4
Affected:
up to 4.3.7
Fixed in:
4.4
Disclosed:
Mar 6, 2023

CVE-2023-7289 on NVD →

Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'pt_cancel_subscription'

medium

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the pt_cancel_subscription function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to...

CVSS:
5.4
Affected:
up to 4.3.7
Fixed in:
4.4
Disclosed:
Mar 6, 2023

CVE-2023-7287 on NVD →

Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'update_profile_preference'

medium

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to chang...

CVSS:
5.4
Affected:
up to 4.3.7
Fixed in:
4.4
Disclosed:
Mar 6, 2023

CVE-2023-7288 on NVD →

Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'check_mollie_account_details'

medium

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_mollie_account_details function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to verif...

CVSS:
4.3
Affected:
up to 4.3.7
Fixed in:
4.4
Disclosed:
Mar 6, 2023

CVE-2023-7293 on NVD →

Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'paytium_notice_dismiss'

medium

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal due to a missing capability check on the paytium_notice_dismiss function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to dis...

CVSS:
4.3
Affected:
up to 4.3.7
Fixed in:
4.4
Disclosed:
Mar 6, 2023

CVE-2023-7292 on NVD →

Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'check_for_verified_profiles'

medium

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_for_verified_profiles function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to check...

CVSS:
4.3
Affected:
up to 4.3.7
Fixed in:
4.4
Disclosed:
Mar 6, 2023

CVE-2023-7290 on NVD →

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal due to a missing capability check on the paytium_notice_dismiss function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to dis...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Mar 6, 2023

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the pt_cancel_subscription function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Mar 6, 2023

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_mollie_account function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to set up...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Mar 6, 2023

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_mollie_account_details function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to verif...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Mar 6, 2023

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_for_verified_profiles function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to check...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Mar 6, 2023

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to chang...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Mar 6, 2023

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to create a...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Mar 6, 2023

Paytium: Mollie payment forms &amp; donations [paytium] < 4.4

unknown

The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the paytium_sw_save_api_keys function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to change pl...

Affected:
up to 4.4
Fixed in:
4.4
Disclosed:
Mar 6, 2023

Paytium: Mollie payment forms &amp; donations [paytium] < 4.3.7

unknown

[en] The Paytium: Mollie payment forms & donations WordPress plugin before 4.3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 4.3.7
Fixed in:
4.3.7
Disclosed:
Dec 26, 2022

CVE-2022-4042 on NVD →

Paytium <= 4.3.6 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Paytium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paytium_live_api_key' option and 'newsletter_group' attribute in versions up to, and including, 4.3.6 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbi...

CVSS:
5.5
Affected:
up to 4.3.6
Fixed in:
4.3.7
Disclosed:
Nov 30, 2022

CVE-2022-4042 on NVD →

Paytium <= 3.1.1 - Stored Cross-Site Scripting

medium

The Paytium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_field_data_html()' function in versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will...

CVSS:
6.4
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
May 12, 2020

Paytium: Mollie payment forms &amp; donations [paytium] < 3.1.2

unknown

The Paytium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_field_data_html()' function in versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will...

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
May 12, 2020

Paytium: Mollie payment forms &amp; donations [paytium] < 3.1.2

unknown

Both authenticated and unauthenticated stored XSS issues via fields in the payment details.

Affected:
up to 3.1.2
Fixed in:
3.1.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database