
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2941 is a missing authorization vulnerability in the Linksy Search and Replace plugin for WordPress that allows authenticated attackers with subscriber-level access to escalate their privileges to administrator. The flaw exists in all versions up to and including 1.0.4, affecting the linksy_search_and_replace_item_details function. It was published on March 21, 2026, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, Red Hat CVE).
The root cause is a missing capability check (CWE-862) on the linksy_search_and_replace_item_details AJAX function, which fails to verify whether the requesting user has sufficient privileges before performing database operations. An authenticated attacker with at minimum subscriber-level access can send a crafted request to this function to update arbitrary values in any WordPress database table — including the wp_capabilities field — effectively rewriting their own role to administrator. The vulnerable code path is visible in the plugin source at inc/Admin/Partials/SearchAndReplace/AjaxActions.php#L197 (Wordfence, Plugin Source).
Successful exploitation grants an attacker full administrative control over the WordPress installation, resulting in high confidentiality, integrity, and availability impacts. An attacker who begins with only a subscriber account can modify any database table, install malicious plugins or themes, exfiltrate sensitive data, or completely take over the site. This also creates a pathway for lateral movement if the WordPress database server is shared or if administrative credentials are reused elsewhere (Wordfence).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Wordfence). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039%, indicating a low current probability of exploitation in the near term. However, the low barrier to exploitation — requiring only a valid subscriber account — makes it an attractive target if the plugin remains installed and unpatched.
/wp-content/plugins/linksy-search-and-replace/) or using tools like WPScan./wp-admin/admin-ajax.php) targeting the linksy_search_and_replace_item_details action, with parameters specifying the wp_usermeta or wp_capabilities table and the attacker's user ID as the target row.wp_capabilities: Set the capability value to a:1:{s:13:"administrator";b:1;} (serialized PHP for administrator role) for the attacker's user account./wp-admin/admin-ajax.php with action=linksy_search_and_replace_item_details from low-privilege user accounts; repeated or unusual AJAX calls from subscriber-level users.wp_usermeta table, particularly modifications to the wp_capabilities field for non-administrator accounts; audit log entries showing database writes to capability fields outside of normal admin activity.wp-config.php, or newly created PHP webshells in the WordPress directory following privilege escalation.No patched version of the Linksy Search and Replace plugin was available at the time of disclosure. Site administrators should immediately deactivate and remove the plugin until a fixed version is released (Wordfence). As interim measures: review all user accounts for unauthorized privilege escalations, restrict new user registrations if not required, and implement WAF rules to block unauthorized requests to the linksy_search_and_replace_item_details AJAX action. Database audit logging should be enabled to detect suspicious modifications to the wp_capabilities field.
Wordfence published the vulnerability as part of their weekly WordPress vulnerability report for March 16–22, 2026, flagging it as a high-severity issue (Wordfence Weekly Report). The vulnerability was noted on social media platforms including Mastodon and Bluesky by security community accounts such as RedPacketSecurity, reflecting routine community awareness activity. No major vendor statements or significant media coverage beyond standard vulnerability aggregation were observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."