WordPress Plugin Vulnerabilities

Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator

Description

The plugin does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.

Proof of Concept

Affects Plugins

Fixed in 1.1.5

References

Classification

Miscellaneous

Original Researcher
ryan fabella
Submitter
ryan fabella
Verified
Yes

Timeline

Publicly Published
2026-10-05 (about 2 days ago)
Added
2026-10-05 (about 1 day ago)
Last Updated
2026-10-06 (about 8 hours ago)

Other