CVE-2026-2941Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to update any database table, any value, including the wp_capabilities database field, which allows attackers to change their own role to administrator, which leads to privilege escalation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-21: 4Technical Details · 2026-03-21: 303-21
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-2941 - plugli - Linksy Search and Replace - https://www.redpacketsecurity.com/cve-alert-cve-2026-2941-plugli-linksy-search-and-replace/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-2941 #plugli #linksy-search-and-replace

    Post summary

    The text announces a CVE alert via an external link but provides no substantive technical details, PoC, exploit, or mitigation information.

    0000066
    3.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-2941 - High The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function... https://www.thehackerwire.com/vulnerability/CVE-2026-2941/ https://t.co/wLzLHRfQqV

    Post summary

    The post discloses a high‑severity vulnerability in the Linksy Search and Replace WordPress plugin that permits unauthorized data modification due to a missing capability check, without mentioning PoC, exploitation tools, or patch details.

    0000031
    142 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2941 The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replac… https://www.cve.org/CVERecord?id=CVE-2026-2941

    Post summary

    The text cites a CVE record for a WordPress plugin vulnerability, noting a missing capability check that allows unauthorized data modification, but it does not mention PoC, exploit code, active exploitation, or available patches.

    0000084
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2941: HIGH] WordPress plugin Linksy Search and Replace allows unauthorized data modification due to a missing capability check, affecting versions up to 1.0.4, enabling attackers with subscriber righ...#cve,CVE-2026-2941,#cybersecurity https://cvefind.com/CVE-2026-2941

    Post summary

    The post reports a new WordPress plugin vulnerability (CVE-2026-2941) stemming from a missing capability check that enables unauthorized data modification.

    0000035
    604 followersView on X

Explore more