Skip to main content
Vulnerability Database/CVE-2026-89426

CVE-2026-89426: Knit Pay WordPress Privilege Escalation

CVE-2026-89426 is a privilege escalation vulnerability in the Knit Pay WordPress plugin that allows authenticated attackers to elevate privileges to administrator. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-89426 Overview

The Knit Pay payment plugin for WordPress contains a privilege escalation vulnerability affecting all versions up to and including 9.6.1.0. The flaw resides in the maybe_update_user_role() function within the plugin's Gravity Forms integration. The function reads the target role directly from an attacker-controlled form field and passes it to WP_User::set_role() without validating the value against an allowlist. Authenticated users with Subscriber-level access can elevate privileges to administrator by tampering with a hidden role field at form submission time. The weakness is categorized as Improper Privilege Management [CWE-269].

Critical Impact

Any authenticated user with Subscriber role or higher can gain full administrator control of the WordPress site, leading to complete site compromise.

Affected Products

  • Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress
  • All versions up to and including 9.6.1.0
  • Installations using the Gravity Forms integration with user role assignment feeds

Discovery Timeline

  • 2026-09-25 - CVE-2026-89426 published to NVD
  • 2026-09-25 - Last updated in NVD database

Technical Details for CVE-2026-89426

Vulnerability Analysis

The vulnerability exists in the Gravity Forms extension bundled with Knit Pay, specifically in packages/wp-pay-extensions/gravityforms/src/Extension.php. The maybe_update_user_role() function retrieves the target WordPress role from a Gravity Forms entry field whose ID is configured via the feed's user_role_field_id setting. Because form field values are controlled by the submitter, an authenticated attacker can supply any role string, including administrator. The retrieved value is passed directly to WP_User::set_role() with no server-side validation against a list of permitted roles.

Two additional conditions amplify exploitability. First, orders with a $0 total are synchronously marked as SUCCESS during form submission, bypassing the requirement for a real payment transaction. Second, when the plugin cannot resolve a Gravity Forms User Registration target user, the role assignment falls back to $lead['created_by'] — the ID of the currently authenticated submitter. This fallback transforms any authenticated form submitter into a valid target for role assignment.

Root Cause

The root cause is missing input validation on a security-sensitive parameter. The plugin trusts the role value supplied through a hidden form field without enforcing an allowlist of safe, non-privileged roles. The design also fails to separate payment success state from role assignment logic, allowing free-tier form submissions to trigger administrator role grants.

Attack Vector

An attacker with Subscriber-level access or higher locates a form configured with a Knit Pay feed that includes user_role_field_id. The attacker modifies the hidden role field in the client-side form markup, submits the form with a $0 total, and the plugin assigns the chosen role to the attacker's own account. See the Wordfence Vulnerability Report and the vulnerable Knit Pay Extension Code Snippet for the technical mechanics.

Detection Methods for CVE-2026-89426

Indicators of Compromise

  • Unexpected wp_capabilities user meta changes assigning administrator or other elevated roles to recently registered accounts.
  • Gravity Forms entries containing non-standard values in fields referenced by Knit Pay feed user_role_field_id settings.
  • Knit Pay payment records with a $0 total marked as SUCCESS and correlated to the same user whose role changed.
  • New administrator accounts created by Subscriber-level users within the WordPress audit log.

Detection Strategies

  • Audit the wp_usermeta table for recent wp_capabilities modifications and correlate against form submission timestamps.
  • Inspect Gravity Forms entry data for hidden field values that resolve to WordPress role slugs such as administrator, editor, or shop_manager.
  • Review Knit Pay transaction logs for $0 orders that completed synchronously without a payment gateway callback.

Monitoring Recommendations

  • Enable WordPress role change logging through a reputable activity log plugin and alert on any elevation to administrator.
  • Monitor web access logs for POST requests to Gravity Forms submission endpoints originating from low-privilege authenticated sessions.
  • Alert on creation of new administrator-capability users outside of expected provisioning workflows.

How to Mitigate CVE-2026-89426

Immediate Actions Required

  • Update the Knit Pay plugin to a version later than 9.6.1.0 as soon as the vendor publishes a fixed release.
  • Audit all WordPress user accounts for unauthorized role elevations and revoke administrator access from unexpected users.
  • Review Gravity Forms feeds configured with Knit Pay and remove or restrict any user_role_field_id setting that references a user-controllable field.

Patch Information

Refer to the Knit Pay Change Set Details for the vendor's remediation changeset. Administrators should verify the installed plugin version against the fixed release referenced in the Wordfence Vulnerability Report.

Workarounds

  • Disable the Knit Pay Gravity Forms integration until the plugin is patched.
  • Remove any Knit Pay feed configuration that assigns WordPress roles based on form field input.
  • Restrict Subscriber-level account creation and require administrator approval for new registrations.
  • Place the WordPress admin and Gravity Forms submission endpoints behind a Web Application Firewall rule that blocks role slug values in form payloads.
bash
# Configuration example: audit for unauthorized administrator accounts
wp user list --role=administrator --fields=ID,user_login,user_registered,user_email

# Revoke administrator capability from a compromised account
wp user remove-role <user_id> administrator
wp user add-role <user_id> subscriber

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.