Paytium: Mollie payment forms & donations <= 5.0.2 - Unauthenticated Privilege Escalation
critical
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.2. This makes it possible for unauthenticated attackers to elevate their privileges.
- CVSS:
- 9.8
- Affected:
- up to 5.0.2
- Fixed in:
- 5.0.3
- Disclosed:
- Jun 23, 2026
CVE-2026-56030 on NVD →
Paytium <= 4.4.11 - Unauthenticated Full Path Disclosure
medium
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.4.11. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed...
- CVSS:
- 5.3
- Affected:
- up to 4.4.11
- Fixed in:
- 4.4.12
- Disclosed:
- Jan 24, 2025
CVE-2025-24552 on NVD →
Paytium: Mollie payment forms & donations [paytium] < 4.4.12
unknown
[en] Generation of Error Message Containing Sensitive Information vulnerability in David de Boer Paytium allows Retrieve Embedded Sensitive Data. This issue affects Paytium: from n/a through 4.4.11.
- Affected:
- up to 4.4.12
- Fixed in:
- 4.4.12
- Disclosed:
- Jan 24, 2025
CVE-2025-24552 on NVD →
Paytium: Mollie payment forms & donations [paytium] < 4.4.11
unknown
[en] Missing Authorization vulnerability in David de Boer Paytium.This issue affects Paytium: from n/a through 4.4.10.
- Affected:
- up to 4.4.11
- Fixed in:
- 4.4.11
- Disclosed:
- Dec 31, 2024
CVE-2024-51667 on NVD →
Paytium <= 4.4.10 - Missing Authorization
medium
The Paytium plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the paytium_emails_attachments() function in versions up to, and including, 4.4.10. This makes it possible for authenticated attackers, with subscriber-level access and above, to get attachment data.
- CVSS:
- 4.3
- Affected:
- up to 4.4.10
- Fixed in:
- 4.4.11
- Disclosed:
- Nov 1, 2024
CVE-2024-51667 on NVD →
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to crea...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Oct 16, 2024
CVE-2023-7294 on NVD →
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the paytium_sw_save_api_keys function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to chan...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Oct 16, 2024
CVE-2023-7289 on NVD →
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Oct 16, 2024
CVE-2023-7288 on NVD →
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal due to a missing capability check on the paytium_notice_dismiss function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access t...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Oct 16, 2024
CVE-2023-7292 on NVD →
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_mollie_account_details function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Oct 16, 2024
CVE-2023-7293 on NVD →
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_mollie_account function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to s...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Oct 16, 2024
CVE-2023-7291 on NVD →
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_for_verified_profiles function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to c...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Oct 16, 2024
CVE-2023-7290 on NVD →
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
[en] The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the pt_cancel_subscription function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level acces...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Oct 16, 2024
CVE-2023-7287 on NVD →
Paytium: Mollie payment forms & donations [paytium] < 4.4.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David de Boer Paytium: Mollie payment forms & donations allows Stored XSS.This issue affects Paytium: Mollie payment forms & donations: from n/a through 4.4.2.
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.3
- Disclosed:
- Mar 13, 2024
CVE-2024-25099 on NVD →
Paytium: Mollie payment forms & donations <= 4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
medium
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac...
- CVSS:
- 6.4
- Affected:
- up to 4.4.2
- Fixed in:
- 4.4.3
- Disclosed:
- Feb 12, 2024
CVE-2024-25099 on NVD →
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
Update the WordPress Paytium: Mollie payment forms & donations plugin to the latest available version (at least 4.4).
Unknown discovered and reported this Broken Access Control vulnerability in WordPress Paytium: Mollie payment forms & donations Plugin. This vulnerability has been fixed in version 4.4.
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Mar 8, 2023
Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'create_mollie_account'
high
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_mollie_account function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to set up...
- CVSS:
- 7.1
- Affected:
- up to 4.3.7
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
CVE-2023-7291 on NVD →
Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'create_mollie_profile'
high
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to create a...
- CVSS:
- 7.1
- Affected:
- up to 4.3.7
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
CVE-2023-7294 on NVD →
Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'paytium_sw_save_api_keys'
medium
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the paytium_sw_save_api_keys function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to change pl...
- CVSS:
- 5.4
- Affected:
- up to 4.3.7
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
CVE-2023-7289 on NVD →
Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'pt_cancel_subscription'
medium
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the pt_cancel_subscription function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to...
- CVSS:
- 5.4
- Affected:
- up to 4.3.7
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
CVE-2023-7287 on NVD →
Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'update_profile_preference'
medium
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to chang...
- CVSS:
- 5.4
- Affected:
- up to 4.3.7
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
CVE-2023-7288 on NVD →
Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'check_mollie_account_details'
medium
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_mollie_account_details function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to verif...
- CVSS:
- 4.3
- Affected:
- up to 4.3.7
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
CVE-2023-7293 on NVD →
Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'paytium_notice_dismiss'
medium
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal due to a missing capability check on the paytium_notice_dismiss function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to dis...
- CVSS:
- 4.3
- Affected:
- up to 4.3.7
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
CVE-2023-7292 on NVD →
Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'check_for_verified_profiles'
medium
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_for_verified_profiles function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to check...
- CVSS:
- 4.3
- Affected:
- up to 4.3.7
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
CVE-2023-7290 on NVD →
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal due to a missing capability check on the paytium_notice_dismiss function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to dis...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the pt_cancel_subscription function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_mollie_account function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to set up...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_mollie_account_details function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to verif...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_for_verified_profiles function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to check...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preference function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to chang...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to create a...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
Paytium: Mollie payment forms & donations [paytium] < 4.4
unknown
The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the paytium_sw_save_api_keys function in versions up to, and including, 4.3.7. This makes it possible for authenticated attackers with subscriber-level access to change pl...
- Affected:
- up to 4.4
- Fixed in:
- 4.4
- Disclosed:
- Mar 6, 2023
Paytium: Mollie payment forms & donations [paytium] < 4.3.7
unknown
[en] The Paytium: Mollie payment forms & donations WordPress plugin before 4.3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 4.3.7
- Fixed in:
- 4.3.7
- Disclosed:
- Dec 26, 2022
CVE-2022-4042 on NVD →
Paytium <= 4.3.6 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Paytium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paytium_live_api_key' option and 'newsletter_group' attribute in versions up to, and including, 4.3.6 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbi...
- CVSS:
- 5.5
- Affected:
- up to 4.3.6
- Fixed in:
- 4.3.7
- Disclosed:
- Nov 30, 2022
CVE-2022-4042 on NVD →
Paytium <= 3.1.1 - Stored Cross-Site Scripting
medium
The Paytium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_field_data_html()' function in versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.4
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.2
- Disclosed:
- May 12, 2020
Paytium: Mollie payment forms & donations [paytium] < 3.1.2
unknown
The Paytium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_field_data_html()' function in versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will...
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- May 12, 2020
Paytium: Mollie payment forms & donations [paytium] < 3.1.2
unknown
Both authenticated and unauthenticated stored XSS issues via fields in the payment details.
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2