在 9.1.0 之前的 Adenion Blog2Social WordPress 插件中,低权限用户可以枚举 WordPress 用户账户。具体来说, 中的 AJAX 处理函数会将 参数中提供的任意用户 ID 解析为显示名称,但未验证调用者是否有权限读取用户账户数据。这使得任何拥有 权限的用户都能将 WordPress 用户 ID 映射到显示名称,并确认任意 ID 对应的账户是否存在。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Adenion | Blog2Social | 0 ~ 9.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89031 | 5.4 MEDIUM | Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_move_post |
| CVE-2026-89030 | 4.3 MEDIUM | Blog2Social WordPress Plugin < 9.1.0 User Email Disclosure via b2s_search_user |
No comments yet