CVE-2026-87782: Unknown Koinonia Link
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
Affected products
- Unknown Koinonia Link: from 1.1.2, before 1.1.5 (fixed in 1.1.5)
Published 2026-10-07. Last modified 2026-10-07.