WP Vulnerability WatchVulnerability data as of September 17, 2026

Vulnerability alerts / September 16, 2026

Vulnerability in Blog2Social: Social Media Auto Post & Scheduler — CVE-2026-89030

MediumSeverity
CVSS 5.3
Estimated exploit probability
EPSS
50,000+ sitesInstalls
9.1.0Fixed in

What to do now

Update Blog2Social: Social Media Auto Post & Scheduler to 9.1.0 or later.

Affected versions

  • Everything before 9.1.0

Affected: Blog2Social: Social Media Auto Post & Scheduler (plugin, blog2social)

Check: The plugin on wordpress.org / Our record for Blog2Social: Social Media Auto Post & Scheduler

What the vulnerability is

Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2s_search_user AJAX handler in includes/Ajax/Get.php invokes B2S_Tools::searchUser() in includes/Tools.php, which returns the email address of every matching user without restricting access to callers holding the list_users capability, allowing any user with the edit_posts capability to retrieve user email addresses including those of administrators.

This description is reproduced verbatim from the public vulnerability record.

Sources

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts