PT-2026-98389 · WordPress · Knit Pay

·

CVE-2026-89426

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress versions prior to 9.6.1.1
Description An issue exists where the maybe update user role() function reads a target role from a Gravity Forms entry field, configured via the user role field id feed, and passes it to WP User::set role() without validating the value against an allowlist of permitted roles. Authenticated attackers with Subscriber-level access or higher can elevate their privileges to administrator by tampering with the hidden role field during form submission. This is facilitated by $0 orders being marked as SUCCESS synchronously without payment and the role assignment falling back to the $lead['created by'] variable, which represents the authenticated submitter's user ID.
Recommendations Update the plugin to a version newer than 9.6.1.0.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89426

Affected Products

Knit Pay