Impact
The vulnerability in Pronamic Pay up to version 10.1.0 allows an authenticated user with Subscriber-level access or higher to elevate their privileges to Administrator by manipulating a Gravity Forms field that is passed directly to WP_User::set_role. The affected code has no allowlist or permission checks when updating the user role, enabling attackers to assign themselves any role. This flaw can compromise confidentiality, integrity, and availability by granting full administrative control.
Affected Systems
WordPress sites running the Pronamic Pay plugin version 10.1.0 or earlier with a Gravity Forms payment feed configured to "Update User Role". All installations of pronamic:Pronamic Pay that have this capability enabled are impacted.
Risk and Exploitability
The CVSS score is 8.8, indicating a high severity. EPSS suggests the likelihood of exploitation is very low (<1%), and the vulnerability is not yet listed in the CISA KEV catalog, but the presence of the flaw in a widely used plugin means it could be targeted as a low‑probability, high‑impact attack. The attack vector requires at least an authenticated account with Subscriber or higher privileges, after an administrator has configured the plugin to expose the Update User Role option.
OpenCVE Enrichment