Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

Linksy Search and Replace plugin for WordPress: Data Modification Risk

CVE-2026-2941
Summary

The Linksy Search and Replace plugin for WordPress, used in websites, can be exploited by attackers with subscriber-level access to modify any database table, including changing their own role to administrator, potentially leading to unauthorized changes. This issue affects all versions of the plugin up to and including 1.0.4. To protect your website, update the plugin to a fixed version or remove it if possible.

Original title
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in a...
Original description
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to update any database table, any value, including the wp_capabilities database field, which allows attackers to change their own role to administrator, which leads to privilege escalation.
nvd CVSS3.1 8.8
Vulnerability type
CWE-862 Missing Authorization
Published: 21 Mar 2026 · Updated: 21 Mar 2026 · First seen: 21 Mar 2026