No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adenion
Adenion blog2social Wordpress Wordpress wordpress |
|
| Vendors & Products |
Adenion
Adenion blog2social Wordpress Wordpress wordpress |
Wed, 16 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_posts table using only the attacker-supplied b2s_id primary key with no blog_user_id ownership constraint, allowing any user with the edit_posts capability to reschedule, suppress, or alter the publication state of any other user's scheduled social media post. | |
| Title | Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_move_post | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T14:03:03.600Z
Reserved: 2026-09-10T16:23:54.472Z
Link: CVE-2026-89031
No data.
Status : Received
Published: 2026-09-16T15:18:06.057
Modified: 2026-09-16T15:18:06.057
Link: CVE-2026-89031
No data.
OpenCVE Enrichment
Updated: 2026-09-17T04:45:16Z
-
CWE-639
Authorization Bypass Through User-Controlled Key