← Back to search

CVE-2026-89426

8.8 HIGH

Published 2026-09-25 · Updated 2026-09-25

AI risk analysis

Summary
The Knit Pay plugin for WordPress allows authenticated attackers with Subscriber-level access or higher to escalate their privileges to administrator by tampering with the role field in Gravity Forms entries.
Exploitability
Exploitation is relatively easy for authenticated users with Subscriber-level access or higher, as it requires only modifying the role field during form submission.
Blast radius
If exploited, the attacker could gain full administrative control over the WordPress site, leading to potential data breaches and unauthorized access to sensitive information.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Knit Pay version 9.6.2 or later.
auth-bypasswebwp-plugin

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.6.1.0. This is due to the `maybe_update_user_role()` function reading the target role directly from an attacker-controlled Gravity Forms entry field — configured via the feed's `user_role_field_id` — and passing it to `WP_User::set_role()` without validating the supplied value against an allowlist of permitted roles. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to administrator by tampering with the hidden role field value at form submission time. Exploitation is further enabled by the fact that $0 orders are synchronously marked as SUCCESS during form submission without requiring a real payment, and when no GF User Registration user can be resolved, the role assignment target falls back to `$lead['created_by']` — the currently authenticated submitter's own user ID — making any authenticated form submitter an eligible exploitation target.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-269

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.