Impact
A broken access control flaw in WordPress Knit Pay versions 9.6.0.0 and older allows an attacker who is not logged in to reach administrative endpoints and retrieve or modify payment configuration data. The vulnerability, identified as CWE‑862, exposes sensitive transaction information and gives an unauthorized user potential control over how payments are processed, impacting confidentiality and integrity of financial data.
Affected Systems
All WordPress sites that have the Knit Pay plugin installed at version 9.6.0.0 or earlier are affected. The issue is resolved in version 9.6.0.1 and later, so updating the plugin removes the risk.
Risk and Exploitability
The CVSS score of 6.5 classifies the flaw as moderate, but because it is unauthenticated, the potential impact for e‑commerce sites is high. The EPSS score of less than 1% suggests that exploitation is presently unlikely, and the vulnerability is not listed in the CISA KEV catalog, indicating no documented active exploitation. Nonetheless, any user able to send HTTP requests to the vulnerable URLs can trigger the flaw, so the attack vector is network‑based and requires no special privileges.
OpenCVE Enrichment