Description
The Twitter posts to Blog plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dg_tw_options' function in all versions up to, and including, 1.11.25. This makes it possible for unauthenticated attackers to update plugin settings including Twitter API credentials, post author, post status, and the capability required to access the plugin's admin menu.
Published: 2026-02-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized plugin settings modification
Action: Patch
AI Analysis

Impact

The Twitter posts to Blog plugin for WordPress contains a missing capability check in its 'dg_tw_options' function. As a result, anyone who can reach the plugin’s admin page can modify its configuration data without authentication. The exploitable settings include Twitter API credentials, default post author, post status and the required capability to open the plugin’s admin menu. An attacker who succeeds can create posts that appear to come from legitimate accounts, change the author to that of an authorized user, or provoke the plugin to post malicious content to the blog. Because the settings are stored in the database, this vulnerability endangers confidentiality, integrity, and availability of posts and credentials.

Affected Systems

The vulnerability affects all releases of the badbreze Twitter posts to Blog WordPress plugin up to and including version 1.11.25. The affected product is the WordPress plugin “Twitter posts to Blog” provided by the vendor badbreze. No specific operating system or WordPress core version is required; the flaw exists solely inside the plugin code.

Risk and Exploitability

The CVSS vector indicates a moderate severity (score 6.5). The EPSS score of less than 1 % suggests that exploitation is unlikely at the current time, and the flaw is not listed in the CISA KEV catalog. Nevertheless, the lack of an authorization check means that the exploit can be performed over the web by harvesting the plugin’s URL or by sending a crafted POST request. No authentication is required, so any user that can access the WordPress site could, in theory, apply the change. The potential for defacement or credential theft—particularly if the attacker injects compromised Twitter API keys—makes the risk significant for sites that rely on the plugin for automated posting.

Generated by OpenCVE AI on April 15, 2026 at 17:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Twitter posts to Blog plugin to the latest released version that includes an authorization check for the dg_tw_options function.
  • Remove or disable the plugin if it is not required for site functionality, as it no longer receives security updates.
  • If immediate removal is not possible, restrict write permissions to the plugin options table and block unauthenticated access to the WordPress admin area, ensuring that only users with the correct capabilities can send requests to dg_tw_options.

Generated by OpenCVE AI on April 15, 2026 at 17:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 11 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Badbreze
Badbreze twitter Posts To Blog
Wordpress
Wordpress wordpress
Vendors & Products Badbreze
Badbreze twitter Posts To Blog
Wordpress
Wordpress wordpress

Wed, 11 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Feb 2026 08:30:00 +0000

Type Values Removed Values Added
Description The Twitter posts to Blog plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dg_tw_options' function in all versions up to, and including, 1.11.25. This makes it possible for unauthenticated attackers to update plugin settings including Twitter API credentials, post author, post status, and the capability required to access the plugin's admin menu.
Title Twitter posts to Blog <= 1.11.25 - Missing Authorization to Unauthenticated Plugin Settings Update
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Badbreze Twitter Posts To Blog
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:14:42.685Z

Reserved: 2026-02-03T00:06:18.901Z

Link: CVE-2026-1786

cve-icon Vulnrichment

Updated: 2026-02-11T15:41:19.583Z

cve-icon NVD

Status : Deferred

Published: 2026-02-11T09:15:51.690

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-1786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T17:30:10Z

Weaknesses