๐Ÿ” CVE Alert

CVE-2026-87782

UNKNOWN 0.0

Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.

Vendor unknown
Product koinonia link
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for unknown koinonia link

Be the first to know when new unknown vulnerabilities affecting unknown koinonia link are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Koinonia Link
1.1.2 < 1.1.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/0f3af398-4a70-4987-9da8-b876b9e932c7/

Credits

ryan fabella WPScan