Impact
The NextScripts: Social Networks Auto-Poster WordPress plugin before version 4.4.8 accepts AJAX calls that perform credential export, post deletion, and configuration reset without checking the user’s capabilities or ownership of the action, relying solely on a nonce. This allows an authenticated administrator who has been granted posting permissions to retrieve the site’s configured social media account credentials, delete arbitrary posts, or reset the plugin configuration. The exposed social credentials could be used to compromise external social accounts, impacting the confidentiality and integrity of the organization’s social media presence.
Affected Systems
All WordPress sites installing the NextScripts: Social Networks Auto-Poster plugin version 4.4.8 or older. The vulnerability is active on any installation where an administrator user has been given access to the plugin’s posting features.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be an authenticated WordPress user with administrative access to posting features; the attacker can then exploit the missing capability checks to export credentials, delete posts, or reset configuration. As the plugin manages social media credentials, the impact can be high because it exposes data that may be reused to compromise external accounts. No CVSS score is provided in the data, so the exact severity assessment is unknown, but the nature of the exposure suggests a serious risk for sites that rely on this plugin for content distribution.
OpenCVE Enrichment