Adenion · Blog2Social · CVE-2026-89031
Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s calendar move post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s posts table using only the attacker-supplied b2s id primary key with no blog user id ownership constraint, allowing any user with the edit posts capability to reschedule, suppress, or alter the publication state of any other user's scheduled social media post.