Email Disclosure Vulnerability in Adenion Blog2Social for WordPress
CVE-2026-89030

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 September 2026

What is CVE-2026-89030?

The Adenion Blog2Social plugin for WordPress prior to version 9.1.0 contains a vulnerability that allows low-privileged users to access the email addresses of all registered WordPress users. This issue arises from improper access controls in the b2s_search_user AJAX handler. Users with the edit_posts capability can exploit this vulnerability to disclose sensitive email information, including that of administrators, thus jeopardizing user privacy and the overall security of the WordPress installation.

Affected Version(s)

Blog2Social 0 < 9.1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Choriyev Qahramon (ciprobe)
VulnCheck
.