Impact
The Nelio Content plugin suffers from an authorization bypass (CWE‑862) that allows any authenticated user with a contributor role or higher to delete reusable social messages. Deleting these messages removes marketing content and undermines data integrity, potentially erasing content created by administrators or other privileged users.
Affected Systems
All installations of the Nelio Content – Editorial Calendar & Social Media Auto‑Posting WordPress plugin version 4.5.0 or earlier are affected. The flaw exists in the REST controller that handles delete requests for reusable messages.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity and significant impact on confidentiality, integrity, and availability. The vulnerability is not listed in the CISA KEV catalog, and no EPSS score is available. The likely attack vector requires an authenticated user with contributor-level or higher privileges to issue a DELETE request to the plugin’s REST endpoint containing the target message identifier, with no further escalation needed.
OpenCVE Enrichment