CVE-2026-87782: Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator
The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Koinonia Link WordPress pluginto a version that resolves this vulnerability.Fixed in 1.1.5
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated user can exploit it, including a user with only the Subscriber role. The attacker does not need existing administrative privileges.
What access does an attacker gain?
An attacker can assign themselves the Administrator role through a profile update. This gives them administrative privileges in the affected WordPress site.
Which installations are affected?
Koinonia Link versions 1.1.2 through 1.1.4 are affected. The issue is fixed in version 1.1.5.