Email Disclosure Vulnerability in Adenion Blog2Social for WordPress
CVE-2026-89030
5.3MEDIUM
What is CVE-2026-89030?
The Adenion Blog2Social plugin for WordPress prior to version 9.1.0 contains a vulnerability that allows low-privileged users to access the email addresses of all registered WordPress users. This issue arises from improper access controls in the b2s_search_user AJAX handler. Users with the edit_posts capability can exploit this vulnerability to disclose sensitive email information, including that of administrators, thus jeopardizing user privacy and the overall security of the WordPress installation.
Affected Version(s)
Blog2Social 0 < 9.1.0