Junglewise Threat Intelligence

CVE-2026-57717: Knit Pay Broken Access Control in WordPress plugin

CVE-2026-57717 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Executive brief

Knit Pay is a WordPress plugin used to integrate various payment gateways into websites. A security flaw in versions up to 9.6.0.0 allows unauthenticated users to perform actions they should not have permission to access. This could potentially lead to unauthorized changes to payment settings or service disruptions, though the overall impact is considered moderate.

Technical details

A broken access control vulnerability exists in the Knit Pay plugin for WordPress (versions 9.6.0.0 and earlier) due to missing authorization (CWE-862). The flaw allows an unauthenticated remote attacker to trigger functions that should be restricted to higher-privileged users. According to the CVSS vector, the attack is low complexity and requires no user interaction, potentially impacting the integrity and availability of the plugin's functionality. The issue is resolved in version 9.6.0.1.

Affected products

  • Knit Pay Knit Pay <= 9.6.0.0

Timeline

  • 2026-06-27: other: Vulnerability reported by Riyas M S
  • 2026-07-21: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: NVD publication date

References

Related threats