WP Vulnerability WatchVulnerability data as of September 17, 2026

Vulnerability alerts / September 16, 2026

Vulnerability in Blog2Social: Social Media Auto Post & Scheduler — CVE-2026-89029

MediumSeverity
CVSS 5.3
Estimated exploit probability
EPSS
50,000+ sitesInstalls
9.1.0Fixed in

What to do now

Update Blog2Social: Social Media Auto Post & Scheduler to 9.1.0 or later.

Affected versions

  • Everything before 9.1.0

Affected: Blog2Social: Social Media Auto Post & Scheduler (plugin, blog2social)

Check: The plugin on wordpress.org / Our record for Blog2Social: Social Media Auto Post & Scheduler

What the vulnerability is

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs supplied in the owner parameter to display names without verifying that the caller is authorized to read user account data, allowing any user with the edit_posts capability to map WordPress user IDs to display names and confirm account existence for arbitrary IDs.

This description is reproduced verbatim from the public vulnerability record.

Sources

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts