PT-2026-93762 · WordPress · Blog2Social

·

CVE-2026-89030

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Blog2Social plugin for WordPress versions prior to 9.1.0
Description Low-privileged accounts can access the email addresses of all registered WordPress users. The issue occurs because the b2s search user AJAX handler in includes/Ajax/Get.php calls the searchUser() function in includes/Tools.php without verifying if the requester has the list users capability. Consequently, any user with the edit posts capability can retrieve email addresses, including those of administrators.
Recommendations Update Blog2Social plugin for WordPress to version 9.1.0 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89030

Affected Products

Blog2Social