CVE-2026-92829
Received Received - Intake

Authorization Bypass in Blog2Social WordPress Plugin

Vulnerability report for CVE-2026-92829, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: Wordfence

Description

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.1.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to view, modify, or delete other users' Blog2Social records, including disclosing another user's network authentication IDs and scheduled post content, overwriting Open Graph and Twitter Card post metadata on posts they do not own, rebinding another user's social-network authorization, and mass-hiding all users' scheduled posts sitewide. The plugin's b2s_security_nonce is emitted on the post-edit meta box, which Contributors can render, making the nonce available to any authenticated user at that role level or above.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
blog2social blog2social to 9.1.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Blog2Social WordPress plugin up to version 9.1.0 has an authorization bypass flaw. Authenticated users with contributor-level access or higher can perform actions they shouldn't be able to, such as viewing or modifying other users' records. This includes accessing sensitive data like network authentication IDs and scheduled post content.

Detection Guidance

Check WordPress plugin versions for Blog2Social up to 9.1.0. Look for unauthorized modifications to posts or user records. Review logs for unusual activity by contributor-level users.

Impact Analysis

If you use this plugin, attackers with basic access could view or change your scheduled posts, modify metadata on your posts, or even hide all scheduled posts across the site. They might also rebind your social network authorizations without permission.

Mitigation Strategies

Update the Blog2Social plugin to the latest version. Remove contributor-level access for users if not required. Monitor for unauthorized changes to posts or user data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92829. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart