Description
The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Privilege Escalation to Administrator
Action: Immediate Patch
AI Analysis

Impact

The Koinonia Link WordPress plugin releases prior to 1.1.5 contain a flaw that ignores proper authority checks when a user submits a role change as part of a profile update. Any authenticated user, such as a subscriber, can trigger an update that grants them the Administrator role. This results in a full privilege escalation, allowing the attacker to modify site settings, access sensitive data, and potentially disrupt site availability. The weakness is rooted in an improper access control mechanism.

Affected Systems

WordPress sites using the Koinonia Link plugin versions 1.1.2 through 1.1.4 are affected. Users who are not administrators but have normal member or subscriber accounts can exploit the flaw by editing their profile. No other vendors or products are mentioned, and the issue is limited to this plugin version range.

Risk and Exploitability

Although no CVSS score is supplied, the vulnerability enables a legitimate authenticated user to automatically obtain full administrative rights, which is considered a severe risk. The EPSS score is not available, so the current exploitation probability cannot be quantified, but the fact that any authenticated user can trigger the escalation suggests a high likelihood of use in a compromised environment. The attack vector is inferred to be local (authenticated) and automated via the plugin’s profile update endpoint. The vulnerability is not listed in CISA KEV, but the impact of administrator takeover makes it high priority.

Generated by OpenCVE AI on October 7, 2026 at 07:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch to version 1.1.5 or later as soon as possible
  • If delay is required, restrict the "edit_user" capability for subscriber roles through a role‑management plugin or custom code
  • Temporarily remove the role change UI from the profile update page using custom CSS or custom plugin code until a patch is applied

Generated by OpenCVE AI on October 7, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
Title Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T06:00:08.296Z

Reserved: 2026-09-09T09:19:19.570Z

Link: CVE-2026-87782

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T07:17:01.847

Modified: 2026-10-07T07:17:01.847

Link: CVE-2026-87782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T07:30:14Z

Weaknesses