Description
Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs supplied in the owner parameter to display names without verifying that the caller is authorized to read user account data, allowing any user with the edit_posts capability to map WordPress user IDs to display names and confirm account existence for arbitrary IDs.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: User Enumeration
Action: Apply Patch
AI Analysis

Impact

The Blog2Social plugin’s b2s_get_select_mandant_user AJAX handler accepts an arbitrary owner parameter and returns the corresponding display name without checking that the caller is authorized to view that user’s data. A low-privileged user who has the edit_posts capability can therefore submit any numeric user ID, map it to a display name if it exists, and thus confirm the presence or absence of user accounts. This flaw exposes sensitive account information but does not affect the integrity of content or the availability of the site. The vulnerability is a lack of adequate authorization before disclosure, a classic instance of CWE‑639.

Affected Systems

Adenion’s Blog2Social WordPress plugin, versions earlier than 9.1.0, on any WordPress installation that includes the plugin.

Risk and Exploitability

The CVSS score of 5.3 marks the issue as moderate severity, while the EPSS of less than 1% indicates that exploitation attempts are expected to be infrequent. Because the flaw requires the edit_posts capability, an attacker must already possess a low‑privileged role, limiting who can exploit it. The vulnerability is not listed in CISA’s KEV catalog, so no known widespread exploitation has been reported. The attacker’s path involves sending a crafted AJAX request to the exposed endpoint and observing the returned display name to validate user existence.

Generated by OpenCVE AI on September 18, 2026 at 02:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Blog2Social plugin to version 9.1.0 or later to eliminate the vulnerability.
  • Limit the edit_posts capability to trusted users so that only authorized personnel can trigger the AJAX handler.
  • If an upgrade is not immediately possible, block or guard the b2s_get_select_mandant_user AJAX endpoint so that only authenticated administrators can use it, or add server‑side checks that verify the caller’s authorization before returning user data.

Generated by OpenCVE AI on September 18, 2026 at 02:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:adenion:blog2social:*:*:*:*:*:wordpress:*:*

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Adenion
Adenion blog2social
Wordpress
Wordpress wordpress
Vendors & Products Adenion
Adenion blog2social
Wordpress
Wordpress wordpress

Wed, 16 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs supplied in the owner parameter to display names without verifying that the caller is authorized to read user account data, allowing any user with the edit_posts capability to map WordPress user IDs to display names and confirm account existence for arbitrary IDs.
Title Blog2Social WordPress Plugin < 9.1.0 User Enumeration via AJAX Handler
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Adenion Blog2social
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:21:52.173Z

Reserved: 2026-09-10T16:23:54.472Z

Link: CVE-2026-89029

cve-icon Vulnrichment

Updated: 2026-09-17T19:16:40.789Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T14:17:13.040

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-89029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:45:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key