Authorization Bypass in Blog2Social Plugin for WordPress
CVE-2026-92829
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-92829?
The Blog2Social plugin for WordPress is susceptible to an authorization bypass vulnerability in all versions up to 9.1.0. This flaw arises from inadequate verification processes that fail to ensure users have the proper permissions to execute specific actions. Authenticated attackers with contributor-level access can manipulate or access other users’ Blog2Social data. This includes viewing and modifying records, disclosing sensitive information like network authentication IDs, and altering metadata for scheduled posts they do not own. Additionally, the vulnerability allows for actions such as rebinding other users' social media accounts and hiding all users' scheduled posts across the site. The issue is exacerbated by the exposure of the b2s_security_nonce, which is available to authenticated users at the contributor level.
Affected Version(s)
Blog2Social: Social Media Auto Post & Scheduler 0 <= 9.1.0