Description
The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently delete any reusable social message (nc_reusable_social post), including those authored by administrators or other privileged users.
Published: 2026-10-03
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized deletion of reusable social messages by users with contributor-level access
Action: Immediate Patch
AI Analysis

Impact

The Nelio Content plugin suffers from an authorization bypass (CWE‑862) that allows any authenticated user with a contributor role or higher to delete reusable social messages. Deleting these messages removes marketing content and undermines data integrity, potentially erasing content created by administrators or other privileged users.

Affected Systems

All installations of the Nelio Content – Editorial Calendar & Social Media Auto‑Posting WordPress plugin version 4.5.0 or earlier are affected. The flaw exists in the REST controller that handles delete requests for reusable messages.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity and significant impact on confidentiality, integrity, and availability. The vulnerability is not listed in the CISA KEV catalog, and no EPSS score is available. The likely attack vector requires an authenticated user with contributor-level or higher privileges to issue a DELETE request to the plugin’s REST endpoint containing the target message identifier, with no further escalation needed.

Generated by OpenCVE AI on October 3, 2026 at 09:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Nelio Content plugin to version 4.5.1 or later to apply the authorization fix.
  • If an upgrade cannot be performed immediately, remove the delete capability from the contributor role or otherwise reduce contributor permissions so they cannot access or invoke the REST endpoint used to delete reusable messages.
  • Configure server or application level filtering to block HTTP DELETE requests to the plugin’s reusable‑message endpoint for non‑administrator users, providing an additional layer of protection while the official patch is applied.

Generated by OpenCVE AI on October 3, 2026 at 09:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently delete any reusable social message (nc_reusable_social post), including those authored by administrators or other privileged users.
Title Nelio Content <= 4.5.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Reusable Message Deletion via 'id' Parameter
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:41.610Z

Reserved: 2026-09-21T18:23:48.273Z

Link: CVE-2026-94505

cve-icon Vulnrichment

Updated: 2026-10-03T15:38:41.945Z

cve-icon NVD

Status : Received

Published: 2026-10-03T07:16:49.033

Modified: 2026-10-03T16:16:45.360

Link: CVE-2026-94505

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T09:30:19Z

Weaknesses