CVE-2026-87782 PUBLISHED

Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator

Assigner: WPScan
Reserved: 09.09.2026 Published: 07.10.2026 Updated: 07.10.2026

The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.

Product Status

Vendor Unknown
Product Koinonia Link
Versions Default: unaffected
  • affected from 1.1.2 to 1.1.5 (excl.)

Credits

  • ryan fabella finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE