Impact
The Blog2Social WordPress plugin version 9.0 and earlier contains an unprotected AJAX endpoint that exposes all user email addresses to any site user with edit_posts capability. The b2s_search_user handler calls a function that returns email addresses without verifying the caller has list_users capability. As a result, a low-privileged user can uncover the contact information of all users, including administrators.
Affected Systems
Affected systems are WordPress sites running any Blog2Social plugin before 9.1.0, provided by Adenion. The vulnerability is present in every installation of the plugin that has retained the old includes/Ajax/Get.php and Tools.php scripts. Site owners using versions 9.0.x or earlier are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. The EPSS score is less than 1%, implying that exploitation prevalence is expected to be low, and the vulnerability is not yet listed in CISA's KEV catalogue. Attackers only need to possess the edit_posts capability, a common role for contributors, to trigger the vulnerable AJAX call and retrieve all user email addresses. No additional privileges or external conditions are required for exploitation.
OpenCVE Enrichment