Junglewise Threat Intelligence

CVE-2026-49070: Knit Pay broken access control in WordPress plugin

CVE-2026-49070 · Severity: high · CVSS 7.5 · Published 2026-06-15

Executive brief

Knit Pay is a WordPress plugin used to integrate various payment gateways into a website. A security flaw in versions 9.4.0.0 and earlier allows unauthorized individuals to perform actions that should be restricted to administrators. This could lead to unauthorized changes to payment settings or other administrative configurations, potentially impacting the integrity of financial transactions.

Technical details

The Knit Pay plugin for WordPress (versions <= 9.4.0.0) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). A remote, unauthenticated attacker can exploit this flaw by sending crafted requests to vulnerable functions that fail to verify user permissions or nonces. Successful exploitation allows the attacker to execute high-privileged actions, primarily impacting the integrity of the plugin's configuration. The issue is resolved in version 9.4.0.1.

Affected products

  • Knit Pay Knit Pay <= 9.4.0.0

Timeline

  • 2026-05-30: other: Reported by Averon Averenkov
  • 2026-06-08: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References

Related threats