CVE-2026-97227
NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credential Disclosure and Data Deletion
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials, delete arbitrary posts and reset the NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8's configuration.
| Vendor | unknown |
| Product | nextscripts: social networks auto-poster |
| Published | Sep 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown nextscripts: social networks auto-poster
Be the first to know when new unknown vulnerabilities affecting unknown nextscripts: social networks auto-poster are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / NextScripts: Social Networks Auto-Poster
0 < 4.4.8
References
Credits
Dmitrii Ignatyev WPScan