Impact
The Adenion Blog2Social plugin for WordPress before version 9.1.0 has a broken access control flaw in the b2s_calendar_move_post AJAX handler. The endpoint updates the b2s_posts table using only an attacker‑supplied record ID without checking ownership, enabling any user with the edit_posts capability to reschedule, suppress, or otherwise modify another user’s scheduled social media posts.
Affected Systems
The vulnerability exists on any WordPress site that runs the Adenion Blog2Social plugin with a version lower than 9.1.0. Users who possess the edit_posts capability on such installations are at risk of unauthorized changes to other users’ scheduled posts.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by sending a crafted AJAX request to the b2s_calendar_move_post endpoint, which is reachable to authenticated users with the edit_posts capability, thereby enabling unauthorized modification of other users’ scheduled posts.
OpenCVE Enrichment