CVE-2026-89031
Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_move_post
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_posts table using only the attacker-supplied b2s_id primary key with no blog_user_id ownership constraint, allowing any user with the edit_posts capability to reschedule, suppress, or alter the publication state of any other user's scheduled social media post.
| CWE | CWE-639 |
| Vendor | adenion |
| Product | blog2social |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for adenion blog2social
Be the first to know when new medium vulnerabilities affecting adenion blog2social are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
Affected Versions
Adenion / Blog2Social
0 < 9.1.0
References
Credits
Choriyev Qahramon (ciprobe) VulnCheck