Impact
The vulnerability in the Blog2Social WordPress plugin arises because the code fails to verify whether a user is authorized to execute certain actions. As a result, a user with contributor-level access or higher can view, modify, or delete other users' social‑media scheduling records. An attacker may expose network authentication IDs, scheduled post content, overwrite Open Graph and Twitter Card metadata on posts not owned by them, rebind another user’s social‑network authorization, or globally hide all users’ scheduled posts. This breach undermines the confidentiality, integrity, and availability of the plugin’s social‑media integration features.
Affected Systems
WordPress sites that have the Blog2Social plugin up through version 9.1.0 are impacted. The plugin’s b2s_security_nonce is output in the post‑edit meta box, making it accessible to any authenticated user with contributor privileges or higher. Sites that have not yet upgraded beyond 9.1.0 remain vulnerable until the plugin is patched or removed.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity level. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is an authenticated user who holds contributor level or greater. Exploitation requires only normal website interaction with the AJAX endpoints present in the plugin; no advanced privileges or code execution are necessary. Because many WordPress installations use a contributor role, and the exploit path is straightforward, the overall risk to affected sites is moderate.
OpenCVE Enrichment