Unauthorized Data Modification Vulnerability in Blog2Social Plugin for WordPress
CVE-2025-13558

5.4MEDIUM

What is CVE-2025-13558?

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable due to a missing capability check in the 'deleteUserCcDraftPost' function. This oversight allows authenticated users with Subscriber-level access and above to alter the status of any post, including sending them to the trash, thus compromising the integrity of user-generated content. This vulnerability is present in all versions up to and including 8.7.0, making it essential for users to update and secure their installations.

Affected Version(s)

Blog2Social: Social Media Auto Post & Scheduler * <= 8.7.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.