PT-2026-93763 · Adenion · Blog2Social

·

CVE-2026-89031

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s calendar move post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s posts table using only the attacker-supplied b2s id primary key with no blog user id ownership constraint, allowing any user with the edit posts capability to reschedule, suppress, or alter the publication state of any other user's scheduled social media post.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89031

Affected Products

Blog2Social