PT-2026-93763 · Adenion · Blog2Social
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s calendar move post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s posts table using only the attacker-supplied b2s id primary key with no blog user id ownership constraint, allowing any user with the edit posts capability to reschedule, suppress, or alter the publication state of any other user's scheduled social media post.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blog2Social