CVE-2026-97227
Received Received - Intake

Unauthenticated Credential Export in NextScripts SNAP WordPress Plugin

Vulnerability report for CVE-2026-97227, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: WPScan

Description

The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials, delete arbitrary posts and reset the NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8's configuration.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-27
AI Q&A
2026-09-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nextscripts social_networks_auto_poster to 4.4.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the NextScripts: Social Networks Auto-Poster WordPress plugin before version 4.4.8. It allows users with access to posting features to exploit insufficient capability checks on AJAX actions. By relying only on nonces for security, attackers can export social account credentials, delete posts, and reset plugin settings.

Detection Guidance

Check if the NextScripts: Social Networks Auto-Poster plugin is installed and verify its version. If it is below 4.4.8, the system is vulnerable. Look for unauthorized export of social account credentials, deletion of posts, or plugin configuration resets.

Impact Analysis

If you use the vulnerable plugin version, an attacker with posting access could steal your social media account credentials, delete important posts, or reset the plugin's configuration. This could disrupt your social media automation and expose sensitive account details.

Compliance Impact

This vulnerability could lead to unauthorized access to social account credentials and deletion of posts, potentially violating data protection requirements under GDPR and HIPAA if sensitive data is exposed or altered. Unauthorized credential export may result in breaches of confidentiality, while arbitrary post deletion could compromise data integrity.

Mitigation Strategies

Update the NextScripts: Social Networks Auto-Poster plugin to version 4.4.8 or later immediately. Review user roles with access to posting features and restrict unnecessary permissions. Monitor for suspicious activities like credential exports or post deletions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97227. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart