Broken Access Control in Social Boost Plugin by WordPress
CVE-2026-97277
7.6HIGH
What is CVE-2026-97277?
The Social Boost plugin for WordPress exhibits a broken access control vulnerability affecting versions up to 3.6.2. This flaw allows unauthorized users to access sensitive functionalities, potentially leading to privilege escalation and unauthorized actions within the application. Website administrators using this plugin should review their settings and update to a secured version to mitigate risks associated with improper access controls.
Affected Version(s)
Social Boost <= 3.6.2