Privilege Escalation Vulnerability in Knit Pay Plugin for WordPress
CVE-2026-89426

8.8HIGH

What is CVE-2026-89426?

The Knit Pay WordPress plugin is susceptible to a privilege escalation flaw that allows authenticated users with Subscriber-level access or higher to escalate their privileges to that of an administrator. This vulnerability arises from the maybe_update_user_role() function improperly handling user role data sourced from an attacker-controlled Gravity Forms entry. By manipulating hidden role fields during form submission, attackers can take advantage of the plugin’s failure to validate role assignments against an allowlist. Additionally, the plugin's logic permits orders marked as SUCCESS without genuine payments, further facilitating exploitation. This vulnerability highlights the critical need for proper role validation to secure user permissions effectively.

Affected Version(s)

Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more 0 <= 9.6.1.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

moonge
.