Impact
The Blog2Social plugin’s b2s_get_select_mandant_user AJAX handler accepts an arbitrary owner parameter and returns the corresponding display name without checking that the caller is authorized to view that user’s data. A low-privileged user who has the edit_posts capability can therefore submit any numeric user ID, map it to a display name if it exists, and thus confirm the presence or absence of user accounts. This flaw exposes sensitive account information but does not affect the integrity of content or the availability of the site. The vulnerability is a lack of adequate authorization before disclosure, a classic instance of CWE‑639.
Affected Systems
Adenion’s Blog2Social WordPress plugin, versions earlier than 9.1.0, on any WordPress installation that includes the plugin.
Risk and Exploitability
The CVSS score of 5.3 marks the issue as moderate severity, while the EPSS of less than 1% indicates that exploitation attempts are expected to be infrequent. Because the flaw requires the edit_posts capability, an attacker must already possess a low‑privileged role, limiting who can exploit it. The vulnerability is not listed in CISA’s KEV catalog, so no known widespread exploitation has been reported. The attacker’s path involves sending a crafted AJAX request to the exposed endpoint and observing the returned display name to validate user existence.
OpenCVE Enrichment