PT-2026-93761 · WordPress · Blog2Social

·

CVE-2026-89029

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Blog2Social plugin for WordPress versions prior to 9.1.0
Description Low-privileged users can enumerate WordPress user accounts. The b2s get select mandant user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs provided in the owner parameter to display names without verifying if the caller is authorized to access user account data. This allows any user with the edit posts capability to map WordPress user IDs to display names and confirm the existence of accounts for arbitrary IDs.
Recommendations Update the Blog2Social plugin for WordPress to version 9.1.0 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89029

Affected Products

Blog2Social