Executive brief
Knit Pay is a WordPress plugin used to integrate various payment gateways into a website. A security flaw in versions 9.4.0.0 and earlier allows unauthorized individuals to perform actions that should be restricted to administrators. This could lead to unauthorized changes to payment settings or other administrative configurations, potentially impacting the integrity of financial transactions.
Technical details
The Knit Pay plugin for WordPress (versions <= 9.4.0.0) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). A remote, unauthenticated attacker can exploit this flaw by sending crafted requests to vulnerable functions that fail to verify user permissions or nonces. Successful exploitation allows the attacker to execute high-privileged actions, primarily impacting the integrity of the plugin's configuration. The issue is resolved in version 9.4.0.1.
Affected products
- Knit Pay Knit Pay <= 9.4.0.0
Timeline
- 2026-05-30: other: Reported by Averon Averenkov
- 2026-06-08: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date