Authorization Bypass in Blog2Social Plugin for WordPress
CVE-2026-4330
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 April 2026
What is CVE-2026-4330?
The Blog2Social plugin for WordPress is vulnerable to an authorization bypass due to insufficient validation of the user-supplied 'b2s_id' parameter. This flaw affects all versions up to and including 8.8.3. Authenticated users with Subscriber-level access and higher can exploit this vulnerability to manipulate other users' scheduled social media posts by performing unauthorized UPDATE and DELETE actions. This may lead to unintended content modifications and disruptions within user accounts.
Affected Version(s)
Blog2Social: Social Media Auto Post & Scheduler 0 <= 8.8.3