All verified exploits

CVE-2026-2941 Linksy Search and Replace Subscriber-to-Admin Privilege Escalation

Deterministic high WordPress Added cve-verified-cve-2026-2941

Detects the Linksy Search and Replace WordPress plugin at version 1.0.4 or earlier, where the linksy_search_and_replace_item_details AJAX action lacks any capability check. Any authenticated subscriber can update arbitrary database tables and values, including wp_capabilities, to escalate their role to administrator.

Related WordPress exploits

Is your app exploitable through CVE-2026-2941?

Scan your domain free