Skip to content
Threat Feed
high advisory

Privilege Escalation in Knit Pay WordPress Plugin

The Knit Pay WordPress plugin allows authenticated users to achieve privilege escalation to administrator via insecure role assignment handled by the Gravity Forms integration.

CVE search metadata

CVE search record: CVE-2026-89426. Severity: high. CVSS: 8.8. KEV: no. Product: Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more (<= 9.6.1.0). Brief: Privilege Escalation in Knit Pay WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-09-knit-pay-privilege-escalation/

The Knit Pay plugin for WordPress (versions 9.6.1.0 and earlier) contains a critical privilege escalation vulnerability. The flaw resides within the maybe_update_user_role() function, which processes user role updates based on Gravity Forms submission data. Specifically, the plugin uses the user_role_field_id configuration to read a requested role from form input and passes this value directly to the WP_User::set_role() function without validating it against an allowlist.

This enables an authenticated user, including those with minimal Subscriber-level access, to manipulate the submitted form data to include an administrator role. Because the plugin processes $0 orders synchronously and assigns roles to the created_by user if no other account is resolved, an attacker can submit a crafted form to unilaterally elevate their own privileges. This vulnerability exposes sites to full administrative account takeover by any authenticated user who can submit a configured Gravity Forms form using the vulnerable plugin component.

Impact

Successful exploitation allows any authenticated user (e.g., a standard Subscriber) to gain full administrative privileges on the target WordPress site. This provides the attacker complete control over the site configuration, content, plugins, and user database, leading to potential site-wide compromise, data exfiltration, or further malware deployment.

Recommendation

  • Update the Knit Pay WordPress plugin to the version released after 9.6.1.0 immediately to patch CVE-2026-89426.
  • Review all existing Gravity Forms feeds integrated with Knit Pay to ensure no hidden user role fields are exposed to unauthorized users.
  • Audit existing user accounts for unexpected elevation to the 'administrator' role since the implementation of the plugin.

Immediate actions

Patch Knit Pay plugin to latest version post-9.6.1.0.

IT Operations 24h

Enrichment needed

  • Identify all WordPress sites in the environment running Knit Pay. (SOC) Asset discovery to determine exposure.

Mitigations

Disable Gravity Forms integration for Knit Pay until patch is applied.

immediate IT Operations

CVE-2026-89426

Detection coverage 1

Detects CVE-2026-89426 Exploitation - Privilege Escalation via Knit Pay Plugin

high

Detects suspicious POST requests to WordPress that include parameters commonly used by Gravity Forms and the Knit Pay plugin, specifically looking for indicators of role modification attempts in form submissions.

sigma tactics: privilege-escalation techniques: T1068 sources: webserver

Detection queries are available on the platform. Get full rules →