Knit Pay · Upi Qr Code Payment Gateway For Woocommerce · CVE-2026-56023
**Name of the Vulnerable Software and Affected Versions**
UPI QR Code Payment Gateway for WooCommerce versions prior to 1.6.3
**Description**
The UPI QR Code Payment Gateway for WooCommerce plugin for WordPress contains a broken access control flaw. This issue occurs due to a missing capability check within a function, allowing authenticated users with customer-level permissions or higher to perform unauthorized actions.
**Recommendations**
Update the plugin to a version newer than 1.6.2.