Impact
The Koinonia Link WordPress plugin releases prior to 1.1.5 contain a flaw that ignores proper authority checks when a user submits a role change as part of a profile update. Any authenticated user, such as a subscriber, can trigger an update that grants them the Administrator role. This results in a full privilege escalation, allowing the attacker to modify site settings, access sensitive data, and potentially disrupt site availability. The weakness is rooted in an improper access control mechanism.
Affected Systems
WordPress sites using the Koinonia Link plugin versions 1.1.2 through 1.1.4 are affected. Users who are not administrators but have normal member or subscriber accounts can exploit the flaw by editing their profile. No other vendors or products are mentioned, and the issue is limited to this plugin version range.
Risk and Exploitability
Although no CVSS score is supplied, the vulnerability enables a legitimate authenticated user to automatically obtain full administrative rights, which is considered a severe risk. The EPSS score is not available, so the current exploitation probability cannot be quantified, but the fact that any authenticated user can trigger the escalation suggests a high likelihood of use in a compromised environment. The attack vector is inferred to be local (authenticated) and automated via the plugin’s profile update endpoint. The vulnerability is not listed in CISA KEV, but the impact of administrator takeover makes it high priority.
OpenCVE Enrichment