CVE-2026-89426 (CVSS 8.8): The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and in (opens in a new tab)
Why readAnyone with a Subscriber account on a site running Knit Pay 9.6.1.0 or earlier can hand themselves the administrator role through a hidden form field.
Knit Pay's maybe_update_user_role() takes the target role straight from a Gravity Forms entry field named by the feed's user_role_field_id and passes it to WP_User::set_role() with no allowlist check. Two design choices make it trivially reachable: $0 orders are marked SUCCESS synchronously at submission with no real payment, and when no registered user resolves, the role is applied to $lead['created_by'], meaning the submitter's own account. Sites using Knit Pay with Gravity Forms and open registration should update immediately and audit for unexpected administrator accounts.