PT-2026-98389 · WordPress · Knit Pay
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress versions prior to 9.6.1.1
Description
An issue exists where the
maybe update user role() function reads a target role from a Gravity Forms entry field, configured via the user role field id feed, and passes it to WP User::set role() without validating the value against an allowlist of permitted roles. Authenticated attackers with Subscriber-level access or higher can elevate their privileges to administrator by tampering with the hidden role field during form submission. This is facilitated by $0 orders being marked as SUCCESS synchronously without payment and the role assignment falling back to the $lead['created by'] variable, which represents the authenticated submitter's user ID.Recommendations
Update the plugin to a version newer than 9.6.1.0.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Knit Pay