CVE-2026-87782
Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
| Vendor | unknown |
| Product | koinonia link |
| Published | Oct 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown koinonia link
Be the first to know when new unknown vulnerabilities affecting unknown koinonia link are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Koinonia Link
1.1.2 < 1.1.5
References
Credits
ryan fabella WPScan