CVE-2026-87782 - Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator
CVE ID :CVE-2026-87782
Published : Oct. 7, 2026, 7:17 a.m. | 29 minutes ago
Description :The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 7, 2026, 7:17 a.m. | 29 minutes ago
Description :The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...