CVE-2026-89426 | Knit Pay Plugin up to 9.6.1.0 on WordPress maybe_update_user_role lead[created_by] privileges management

SecurityVulns

A vulnerability, which was classified as critical, has been found in Knit Pay Plugin up to 9.6.1.0 on WordPress. Impacted is the function maybe_update_user_role. The manipulation of the argument lead[created_by] leads to improper privilege management.

This vulnerability is referenced as CVE-2026-89426. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More