๐Ÿ” CVE Alert

CVE-2026-89030

MEDIUM 4.3

Blog2Social WordPress Plugin < 9.1.0 User Email Disclosure via b2s_search_user

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2s_search_user AJAX handler in includes/Ajax/Get.php invokes B2S_Tools::searchUser() in includes/Tools.php, which returns the email address of every matching user without restricting access to callers holding the list_users capability, allowing any user with the edit_posts capability to retrieve user email addresses including those of administrators.

CWE CWE-862
Vendor adenion
Product blog2social
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for adenion blog2social

Be the first to know when new medium vulnerabilities affecting adenion blog2social are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

Adenion / Blog2Social
0 < 9.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordpress.org: https://wordpress.org/plugins/blog2social/#developers vulncheck.com: https://www.vulncheck.com/advisories/blog2social-wordpress-plugin-user-email-disclosure-via-b2s-search-user

Credits

Choriyev Qahramon (ciprobe) VulnCheck