Description
Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_posts table using only the attacker-supplied b2s_id primary key with no blog_user_id ownership constraint, allowing any user with the edit_posts capability to reschedule, suppress, or alter the publication state of any other user's scheduled social media post.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Broken Access Control allowing unauthorized modification of scheduled posts
Action: Immediate Patch
AI Analysis

Impact

The Adenion Blog2Social plugin for WordPress before version 9.1.0 has a broken access control flaw in the b2s_calendar_move_post AJAX handler. The endpoint updates the b2s_posts table using only an attacker‑supplied record ID without checking ownership, enabling any user with the edit_posts capability to reschedule, suppress, or otherwise modify another user’s scheduled social media posts.

Affected Systems

The vulnerability exists on any WordPress site that runs the Adenion Blog2Social plugin with a version lower than 9.1.0. Users who possess the edit_posts capability on such installations are at risk of unauthorized changes to other users’ scheduled posts.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by sending a crafted AJAX request to the b2s_calendar_move_post endpoint, which is reachable to authenticated users with the edit_posts capability, thereby enabling unauthorized modification of other users’ scheduled posts.

Generated by OpenCVE AI on September 18, 2026 at 03:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Blog2Social plugin to version 9.1.0 or newer.
  • Revoke or restrict the edit_posts capability for untrusted or low‑privileged user roles.
  • Block or limit access to the b2s_calendar_move_post AJAX endpoint using a web application firewall or role‑based access controls.

Generated by OpenCVE AI on September 18, 2026 at 03:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:adenion:blog2social:*:*:*:*:*:wordpress:*:*

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Adenion
Adenion blog2social
Wordpress
Wordpress wordpress
Vendors & Products Adenion
Adenion blog2social
Wordpress
Wordpress wordpress

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_posts table using only the attacker-supplied b2s_id primary key with no blog_user_id ownership constraint, allowing any user with the edit_posts capability to reschedule, suppress, or alter the publication state of any other user's scheduled social media post.
Title Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_move_post
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Adenion Blog2social
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:21:53.408Z

Reserved: 2026-09-10T16:23:54.472Z

Link: CVE-2026-89031

cve-icon Vulnrichment

Updated: 2026-09-21T17:45:04.068Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:18:06.057

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-89031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:00:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key