Description
Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2s_search_user AJAX handler in includes/Ajax/Get.php invokes B2S_Tools::searchUser() in includes/Tools.php, which returns the email address of every matching user without restricting access to callers holding the list_users capability, allowing any user with the edit_posts capability to retrieve user email addresses including those of administrators.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Email Disclosure
Action: Update Plugin
AI Analysis

Impact

The Blog2Social WordPress plugin version 9.0 and earlier contains an unprotected AJAX endpoint that exposes all user email addresses to any site user with edit_posts capability. The b2s_search_user handler calls a function that returns email addresses without verifying the caller has list_users capability. As a result, a low-privileged user can uncover the contact information of all users, including administrators.

Affected Systems

Affected systems are WordPress sites running any Blog2Social plugin before 9.1.0, provided by Adenion. The vulnerability is present in every installation of the plugin that has retained the old includes/Ajax/Get.php and Tools.php scripts. Site owners using versions 9.0.x or earlier are at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact. The EPSS score is less than 1%, implying that exploitation prevalence is expected to be low, and the vulnerability is not yet listed in CISA's KEV catalogue. Attackers only need to possess the edit_posts capability, a common role for contributors, to trigger the vulnerable AJAX call and retrieve all user email addresses. No additional privileges or external conditions are required for exploitation.

Generated by OpenCVE AI on September 18, 2026 at 02:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Blog2Social plugin to version 9.1.0 or newer to remove the vulnerable endpoint.
  • Delete legacy AJAX files such as includes/Ajax/Get.php and related tool files to prevent accidental exposure until the patch is in place.
  • Add a capability check to the b2s_search_user endpoint or otherwise block AJAX access to users lacking the list_users capability.

Generated by OpenCVE AI on September 18, 2026 at 02:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:adenion:blog2social:*:*:*:*:*:wordpress:*:*

Thu, 17 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Adenion
Adenion blog2social
Wordpress
Wordpress wordpress
Vendors & Products Adenion
Adenion blog2social
Wordpress
Wordpress wordpress

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2s_search_user AJAX handler in includes/Ajax/Get.php invokes B2S_Tools::searchUser() in includes/Tools.php, which returns the email address of every matching user without restricting access to callers holding the list_users capability, allowing any user with the edit_posts capability to retrieve user email addresses including those of administrators.
Title Blog2Social WordPress Plugin < 9.1.0 User Email Disclosure via b2s_search_user
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Adenion Blog2social
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:21:52.765Z

Reserved: 2026-09-10T16:23:54.472Z

Link: CVE-2026-89030

cve-icon Vulnrichment

Updated: 2026-09-16T15:26:24.521Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T14:17:13.193

Modified: 2026-09-24T20:43:32.537

Link: CVE-2026-89030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:45:17Z

Weaknesses