Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_move_post
Published Sep 16, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.30%
Description
Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_posts table using only the attacker-supplied b2s_id primary key with no blog_user_id ownership constraint, allowing any user with the edit_posts capability to reschedule, suppress, or alter the publication state of any other user's scheduled social media post.
Affected products
-
- Version 0StatusaffectedConstraints<9.1.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Adenion | Blog2Social | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-80775 Advisory
- https://wordpress.org/plugins/blog2social/#developers release-notespatch
- https://www.vulncheck.com/advisories/blog2social-wordpress-plugin-broken-access-control-via-b2s-calendar-move-post third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-80775 | Advisory | |
| https://wordpress.org/plugins/blog2social/#developers | release-notespatch | |
| https://www.vulncheck.com/advisories/blog2social-wordpress-plugin-broken-access-control-via-b2s-calendar-move-post | third-party-advisory |
Change history (0)
No recorded changes yet.