← Volver a CVEs
CVE-2026-4330
MEDIUM4.3
Descripcion
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through user-controlled key in all versions up to, and including, 8.8.3. This is due to the plugin's AJAX handlers failing to validate that the user-supplied 'b2s_id' parameter belongs to the current user before performing UPDATE and DELETE operations. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify, reschedule, or delete other users' scheduled social media posts.
Detalles CVE
Puntuacion CVSS v3.14.3
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado4/8/2026
Ultima modificacion4/8/2026
Fuentenvd
Avistamientos honeypot0
Debilidades (CWE)
CWE-639
Referencias
https://plugins.trac.wordpress.org/browser/blog2social/tags/8.8.2/includes/Ajax/Post.php#L2178(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/blog2social/tags/8.8.2/includes/Ajax/Post.php#L2183(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/blog2social/tags/8.8.2/includes/Ajax/Post.php#L2273(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/blog2social/tags/8.8.2/includes/Ajax/Post.php#L2322(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/blog2social/tags/8.8.2/includes/B2S/Post/Tools.php#L32(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/blog2social/tags/8.8.2/includes/B2S/Ship/Save.php#L190(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/blog2social/tags/8.8.2/includes/Loader.php#L2202(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/blog2social/trunk/includes/Ajax/Post.php#L2178(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/blog2social/trunk/includes/Ajax/Post.php#L2183(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/blog2social/trunk/includes/Ajax/Post.php#L2273(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/blog2social/trunk/includes/Ajax/Post.php#L2322(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/blog2social/trunk/includes/B2S/Post/Tools.php#L32(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/blog2social/trunk/includes/B2S/Ship/Save.php#L190(security@wordfence.com)
https://plugins.trac.wordpress.org/browser/blog2social/trunk/includes/Loader.php#L2202(security@wordfence.com)
https://plugins.trac.wordpress.org/changeset/3494550/(security@wordfence.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.