WP Vulnerability WatchVulnerability data as of September 17, 2026

Vulnerability alerts / September 16, 2026

Vulnerability in Blog2Social: Social Media Auto Post & Scheduler — CVE-2026-89031

MediumSeverity
CVSS 5.3
Estimated exploit probability
EPSS
50,000+ sitesInstalls
9.1.0Fixed in

What to do now

Update Blog2Social: Social Media Auto Post & Scheduler to 9.1.0 or later.

Affected versions

  • Everything before 9.1.0

Affected: Blog2Social: Social Media Auto Post & Scheduler (plugin, blog2social)

Check: The plugin on wordpress.org / Our record for Blog2Social: Social Media Auto Post & Scheduler

What the vulnerability is

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_posts table using only the attacker-supplied b2s_id primary key with no blog_user_id ownership constraint, allowing any user with the edit_posts capability to reschedule, suppress, or alter the publication state of any other user's scheduled social media post.

This description is reproduced verbatim from the public vulnerability record.

Sources

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts