Description
The Social Web Suite WordPress plugin through 4.1.12 does not restrict which of its settings may be written through an unauthenticated endpoint, allowing attackers to overwrite arbitrary Social Web Suite WordPress plugin through 4.1.12 options, including the shared secret that guards its own privileged endpoints.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Privilege Escalation via Unauthenticated Settings Update
Action: Immediate Patch
AI Analysis

Impact

The Social Web Suite WordPress plugin version 4.1.12 and earlier exposes an endpoint that accepts requests without authentication. This endpoint can write to any plugin setting, including a shared secret that protects privileged functionality. An attacker who submits a crafted request can overwrite the secret and thereby gain control over the plugin’s privileged commands, effectively elevating privileges within the site.

Affected Systems

All installations of the Social Web Suite WordPress plugin with a version of 4.1.12 or earlier. The product is managed by the unknown social web suite vendor, and the vulnerability only applies to the plugin itself, not to WordPress core or other plugins.

Risk and Exploitability

Because the vulnerable endpoint is publicly accessible, exploitation does not require credentials or user interaction beyond sending a crafted request. The lack of an EPSS score or listing in the KEV catalog suggests that exploitation has not yet been observed in the wild, but the potential for remote privilege escalation remains significant. The CVSS score is not publicly disclosed, but the nature of the vulnerability—unauthenticated arbitrary write to internal configuration—indicates a high severity likelihood. Attackers could fully control the plugin, enabling further compromise of the site if the privileged commands include malicious code execution or data exfiltration.

Generated by OpenCVE AI on October 9, 2026 at 07:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Social Web Suite plugin to the latest version that removes the unauthenticated settings endpoint.
  • If an update is unavailable, disable or block the vulnerable endpoint using a web application firewall or server configuration rule.
  • Monitor the plugin’s configuration files for unauthorized changes and set up alerts for any modifications to the shared secret or other critical settings.

Generated by OpenCVE AI on October 9, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 09 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Social Web Suite WordPress plugin through 4.1.12 does not restrict which of its settings may be written through an unauthenticated endpoint, allowing attackers to overwrite arbitrary Social Web Suite WordPress plugin through 4.1.12 options, including the shared secret that guards its own privileged endpoints.
Title Social Web Suite <= 4.1.12 - Unauthenticated Arbitrary Plugin Settings Update
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-09T06:00:07.874Z

Reserved: 2026-09-10T14:12:15.089Z

Link: CVE-2026-88931

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T07:17:18.950

Modified: 2026-10-09T07:17:18.950

Link: CVE-2026-88931

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T07:30:18Z

Weaknesses