Authorization Bypass in Blog2Social Plugin for WordPress
CVE-2026-4330

4.3MEDIUM

What is CVE-2026-4330?

The Blog2Social plugin for WordPress is vulnerable to an authorization bypass due to insufficient validation of the user-supplied 'b2s_id' parameter. This flaw affects all versions up to and including 8.8.3. Authenticated users with Subscriber-level access and higher can exploit this vulnerability to manipulate other users' scheduled social media posts by performing unauthorized UPDATE and DELETE actions. This may lead to unintended content modifications and disruptions within user accounts.

Affected Version(s)

Blog2Social: Social Media Auto Post & Scheduler 0 <= 8.8.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mariusz Maik
.