CVE-2026-87782
Description
AI Translation Available
The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
https://wpscan.com/vulnerability/0f3af398-4a70-4987-9da8-b876b9e932c7/