Impact
The vulnerability arises when the plugin’s function reads a role value from an attacker‑controlled Gravity Forms field and passes it directly to WordPress without validation. An authenticated subscriber or higher can modify the hidden role field during form submission, causing the system to assign the attacker the Administrator role. This allows the attacker to gain unrestricted access to the WordPress site, compromising confidentiality, integrity, and availability of all site data.
Affected Systems
All WordPress sites running Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin versions up through 9.6.1.0 are vulnerable. The issue specifically affects installations that use Gravity Forms feeds configured with a user_role_field_id, regardless of the payment gateway involved.
Risk and Exploitability
The CVSS score of 8.8 signals a high‑severity flaw, and the exploitability is high because the attacker only needs a legitimate, authenticated Subscriber account to alter the hidden role field. EPSS data is not available, and the vulnerability is not currently listed in the CISA KEV catalog, but the lack of an allowlist for role values makes exploitation straightforward. If a site allows $0 orders to be processed as successful, the process chooses the current submitter’s user ID as the target, ensuring that any authenticated form submitter can attempt the attack.
OpenCVE Enrichment