Paytium operates a narrowly scoped payment-processing platform whose vulnerability footprint centers on a single product and recurs through web-application weaknesses including missing authorization checks and cross-site scripting. The vendor's durable exposure pattern reflects the authentication and input-handling demands inherent to handling sensitive transaction data. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Paytium over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-7291HIGH The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_mollie_account | Oct 16, 2024 | 8.1 | 22 | NO | NO |
CVE-2022-4042MEDIUM The Paytium: Mollie payment forms & donations WordPress plugin before 4.3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin | Dec 26, 2022 | 4.8 | 19 | NO | NO |
CVE-2023-7294MEDIUM The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the create_mollie_profile fu | Oct 16, 2024 | 6.5 | 18 | NO | NO |
CVE-2023-7289MEDIUM The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized API key update due to a missing capability check on the paytium_sw_save_api_keys fu | Oct 16, 2024 | 4.3 | 16 | NO | NO |
CVE-2023-7287MEDIUM The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized subscription cancellation due to a missing capability check on the pt_cancel_subscr | Oct 16, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-25099MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David de Boer Paytium: Mollie payment forms & donations allows Stored XSS.This | Mar 13, 2024 | 5.4 | 16 | NO | NO |
CVE-2023-7293MEDIUM The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_mollie_account_detail | Oct 16, 2024 | 4.3 | 15 | NO | NO |
CVE-2023-7292MEDIUM The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized notification dismissal due to a missing capability check on the paytium_notice_dism | Oct 16, 2024 | 4.3 | 15 | NO | NO |
CVE-2023-7290MEDIUM The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_for_verified_profiles | Oct 16, 2024 | 4.3 | 15 | NO | NO |
CVE-2023-7288MEDIUM The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_profile_preferenc | Oct 16, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Paytium.
Media articles that mention a CVE ID that affects a product developed by Paytium — matched by CVE ID, not by vendor name.