CVE-2026-88931
Received Received - Intake

Unauthenticated Option Overwrite in Social Web Suite WordPress Plugin

Vulnerability report for CVE-2026-88931, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: WPScan

Description

The Social Web Suite WordPress plugin through 4.1.12 does not restrict which of its settings may be written through an unauthenticated endpoint, allowing attackers to overwrite arbitrary Social Web Suite WordPress plugin through 4.1.12 options, including the shared secret that guards its own privileged endpoints.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Social Web Suite 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability CVE-2026-88931 affects the WordPress plugin Social Web Suite versions 4.1.12 and below. It allows unauthenticated attackers to update arbitrary plugin settings through an unrestricted endpoint. This includes overwriting critical settings like the shared secret that protects privileged plugin functions due to missing authorization checks.

Detection Guidance

Check if the Social Web Suite plugin version 4.1.12 or below is installed. Look for unauthorized modifications to plugin settings, especially the shared secret. Review server logs for suspicious requests to the plugin's endpoints.

Impact Analysis

Attackers could exploit this to modify plugin settings, potentially disabling security features, redirecting users, or gaining unauthorized access to privileged functions. This could lead to site defacement, data breaches, or further compromise of the WordPress installation.

Mitigation Strategies

Disable the Social Web Suite plugin immediately if installed. Monitor for unauthorized changes to plugin settings. Apply any available updates once released. Restrict access to WordPress admin panels and endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88931. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart