Authorization Bypass Vulnerability in Nelio Content Plugin for WordPress
CVE-2026-94505
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-94505?
The Nelio Content β Editorial Calendar & Social Media Auto-Posting plugin for WordPress suffers from an authorization bypass vulnerability in all versions up to and including 4.5.0. This flaw arises because the plugin fails to adequately verify user permissions when executing certain actions. As a result, authenticated attackers with contributor-level access can exploit this vulnerability to permanently delete any reusable social messages, including those created by administrators or other users with higher privileges. This could potentially disrupt content management workflows and result in the loss of important communications. Users are encouraged to update to the latest version to mitigate the risk associated with this vulnerability.
Affected Version(s)
Nelio Content β Editorial Calendar & Social Media Auto-Posting 0 <= 4.5.0