Authorization Bypass in Blog2Social Plugin for WordPress
CVE-2026-92829

4.3MEDIUM

What is CVE-2026-92829?

The Blog2Social plugin for WordPress is susceptible to an authorization bypass vulnerability in all versions up to 9.1.0. This flaw arises from inadequate verification processes that fail to ensure users have the proper permissions to execute specific actions. Authenticated attackers with contributor-level access can manipulate or access other users’ Blog2Social data. This includes viewing and modifying records, disclosing sensitive information like network authentication IDs, and altering metadata for scheduled posts they do not own. Additionally, the vulnerability allows for actions such as rebinding other users' social media accounts and hiding all users' scheduled posts across the site. The issue is exacerbated by the exposure of the b2s_security_nonce, which is available to authenticated users at the contributor level.

Affected Version(s)

Blog2Social: Social Media Auto Post & Scheduler 0 <= 9.1.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Averon Averenkov (Averon Averenkov)
.