Authorization Bypass Vulnerability in Nelio Content Plugin for WordPress
CVE-2026-94505

8.1HIGH

What is CVE-2026-94505?

The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress suffers from an authorization bypass vulnerability in all versions up to and including 4.5.0. This flaw arises because the plugin fails to adequately verify user permissions when executing certain actions. As a result, authenticated attackers with contributor-level access can exploit this vulnerability to permanently delete any reusable social messages, including those created by administrators or other users with higher privileges. This could potentially disrupt content management workflows and result in the loss of important communications. Users are encouraged to update to the latest version to mitigate the risk associated with this vulnerability.

Affected Version(s)

Nelio Content – Editorial Calendar & Social Media Auto-Posting 0 <= 4.5.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.