Description
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials, delete arbitrary posts and reset the NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8's configuration.
Published: 2026-09-27
Score: n/a
EPSS: n/a
KEV: No
Impact: Credential Disclosure and Data Deletion
Action: Patch Immediately
AI Analysis

Impact

The NextScripts: Social Networks Auto-Poster WordPress plugin before version 4.4.8 accepts AJAX calls that perform credential export, post deletion, and configuration reset without checking the user’s capabilities or ownership of the action, relying solely on a nonce. This allows an authenticated administrator who has been granted posting permissions to retrieve the site’s configured social media account credentials, delete arbitrary posts, or reset the plugin configuration. The exposed social credentials could be used to compromise external social accounts, impacting the confidentiality and integrity of the organization’s social media presence.

Affected Systems

All WordPress sites installing the NextScripts: Social Networks Auto-Poster plugin version 4.4.8 or older. The vulnerability is active on any installation where an administrator user has been given access to the plugin’s posting features.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be an authenticated WordPress user with administrative access to posting features; the attacker can then exploit the missing capability checks to export credentials, delete posts, or reset configuration. As the plugin manages social media credentials, the impact can be high because it exposes data that may be reused to compromise external accounts. No CVSS score is provided in the data, so the exact severity assessment is unknown, but the nature of the exposure suggests a serious risk for sites that rely on this plugin for content distribution.

Generated by OpenCVE AI on September 27, 2026 at 08:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the NextScripts: Social Networks Auto-Poster plugin to version 4.4.8 or later immediately.
  • Revoke or rotate the social media account credentials that are stored in the plugin configuration to reduce the potential impact of any leaked credentials.
  • Restrict the plugin’s AJAX capabilities by limiting posting feature access to the minimum necessary user roles, and remove any unused administrator accounts or elevated privileges on the WordPress site.

Generated by OpenCVE AI on September 27, 2026 at 08:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 27 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials, delete arbitrary posts and reset the NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8's configuration.
Title NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credential Disclosure and Data Deletion
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-27T06:00:22.837Z

Reserved: 2026-09-24T09:58:32.449Z

Link: CVE-2026-97227

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T06:17:23.160

Modified: 2026-09-27T06:17:23.160

Link: CVE-2026-97227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T08:15:17Z

Weaknesses