
CVE-2026-16635 - Privilege Escalation in Pronamic Pay WordPress plugin. Auth Subscriber+ can set any role via Gravity Forms. CVSS 8.8. Unpatched - disable or restrict until fix. #CVE #WordPress #infosec #developer #developers #100daysofcode #100daysofcodechallange #git #github #gitlab #redteam #blueteam https://www.valtersit.com/cve/CVE-2026-16635/
Post summary
The post highlights an unpatched privilege‑escalation flaw in the Pronamic Pay WordPress plugin, noting a workaround of disabling or restricting the plugin until a fix is released.

