CVE-2026-87782: Unknown Koinonia Link

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.

Affected products

  • Unknown Koinonia Link: from 1.1.2, before 1.1.5 (fixed in 1.1.5)

Published 2026-10-07. Last modified 2026-10-07.