{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/knit-pay--cashfree-instamojo-razorpay-paypal-and-more--9.6.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:knitpay:knit_pay_-_cashfree,_instamojo,_razorpay,_paypal_and_more:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-89426"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more (\u003c= 9.6.1.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Knit Pay"],"content_html":"\u003cp\u003eThe Knit Pay plugin for WordPress (versions 9.6.1.0 and earlier) contains a critical privilege escalation vulnerability. The flaw resides within the \u003ccode\u003emaybe_update_user_role()\u003c/code\u003e function, which processes user role updates based on Gravity Forms submission data. Specifically, the plugin uses the \u003ccode\u003euser_role_field_id\u003c/code\u003e configuration to read a requested role from form input and passes this value directly to the \u003ccode\u003eWP_User::set_role()\u003c/code\u003e function without validating it against an allowlist.\u003c/p\u003e\n\u003cp\u003eThis enables an authenticated user, including those with minimal Subscriber-level access, to manipulate the submitted form data to include an administrator role. Because the plugin processes $0 orders synchronously and assigns roles to the \u003ccode\u003ecreated_by\u003c/code\u003e user if no other account is resolved, an attacker can submit a crafted form to unilaterally elevate their own privileges. This vulnerability exposes sites to full administrative account takeover by any authenticated user who can submit a configured Gravity Forms form using the vulnerable plugin component.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows any authenticated user (e.g., a standard Subscriber) to gain full administrative privileges on the target WordPress site. This provides the attacker complete control over the site configuration, content, plugins, and user database, leading to potential site-wide compromise, data exfiltration, or further malware deployment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Knit Pay WordPress plugin to the version released after 9.6.1.0 immediately to patch CVE-2026-89426.\u003c/li\u003e\n\u003cli\u003eReview all existing Gravity Forms feeds integrated with Knit Pay to ensure no hidden user role fields are exposed to unauthorized users.\u003c/li\u003e\n\u003cli\u003eAudit existing user accounts for unexpected elevation to the 'administrator' role since the implementation of the plugin.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T10:52:17Z","date_published":"2026-09-25T10:52:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-knit-pay-privilege-escalation/","summary":"The Knit Pay WordPress plugin allows authenticated users to achieve privilege escalation to administrator via insecure role assignment handled by the Gravity Forms integration.","title":"Privilege Escalation in Knit Pay WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-knit-pay-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and More (\u003c= 9.6.1.0)","version":"https://jsonfeed.org/version/1.1"}