The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Wed, 07 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role. | |
| Title | Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-07T06:00:08.296Z
Reserved: 2026-09-09T09:19:19.570Z
Link: CVE-2026-87782
No data.
Status : Received
Published: 2026-10-07T07:17:01.847
Modified: 2026-10-07T07:17:01.847
Link: CVE-2026-87782
No data.
OpenCVE Enrichment
Updated: 2026-10-07T07:30:14Z
Weaknesses