Description
Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.
Published: 2026-10-01
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Broken access control allowing subscriber-level users to modify plugin data
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a broken access control flaw present in the WordPress Social Boost plugin versions up to 3.6.2. The flaw allows users with subscriber-level credentials to perform actions normally restricted to higher‑privilege roles, enabling the modification or deletion of plugin data and settings. The impact is confined to the Social Boost plugin itself and its configuration, potentially altering how the plugin behaves and interacts with the WordPress site.

Affected Systems

WordPress sites that have the Social Boost plugin from Apps Mav installed, with version 3.6.2 or earlier, are vulnerable. Only the plugin component is affected; the core WordPress installation remains unaffected unless the plugin is engaged in processing or storing sensitive information.

Risk and Exploitability

The CVSS score of 7.6 indicates high risk. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be authenticated, as the flaw requires a subscriber account to exploit. Once authenticated, the attacker can bypass normal role checks and alter plugin data, degrading site reliability or compromising the plugin's intended functionality.

Generated by OpenCVE AI on October 1, 2026 at 16:24 UTC.

Remediation

Vendor Solution

Update the WordPress Social Boost plugin to the latest available version (at least 3.7.0).


OpenCVE Recommended Actions

  • Upgrade the Social Boost plugin to version 3.7.0 or newer to eliminate the access‑control issue.
  • If an upgrade cannot be performed immediately, disable or uninstall the Social Boost plugin to remove the vulnerable component.
  • Review user activity logs for abnormal actions originating from subscriber accounts and investigate any suspicious changes to plugin settings.

Generated by OpenCVE AI on October 1, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.
Title WordPress Social Boost plugin <= 3.6.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T16:01:47.829Z

Reserved: 2026-09-24T10:23:19.165Z

Link: CVE-2026-97277

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:38.380

Modified: 2026-10-01T17:17:35.890

Link: CVE-2026-97277

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T16:30:10Z

Weaknesses