🔐 CVE Alert

CVE-2025-58846

UNKNOWN 0.0

WordPress WordPress Buffer – HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule Plugin <= 2020.1.0 - Cross Site Request Forgery (CSRF) Vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cross-Site Request Forgery (CSRF) vulnerability in Dejan Markovic WordPress Buffer – HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule buffer-my-post allows Reflected XSS.This issue affects WordPress Buffer – HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule: from n/a through <= 2020.1.0.

CWE CWE-352
Vendor dejan markovic
Product wordpress buffer – hypesocial. social media auto post, social media auto publish and schedule
Published Sep 5, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for dejan markovic wordpress buffer – hypesocial. social media auto post, social media auto publish and schedule

Be the first to know when new unknown vulnerabilities affecting dejan markovic wordpress buffer – hypesocial. social media auto post, social media auto publish and schedule are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Dejan Markovic / WordPress Buffer – HYPESocial. Social Media Auto Post, Social Media Auto Publish and Schedule
0 ≤ 2020.1.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/buffer-my-post/vulnerability/wordpress-wordpress-buffer-hypesocial-social-media-auto-post-social-media-auto-publish-and-schedule-plugin-2020-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve

Credits

Nguyen Xuan Chien | Patchstack Bug Bounty Program