WordPress 的 Adenion Blog2Social 插件在 9.1.0 版本之前存在漏洞:低权限用户能够修改其他用户的已排期帖子记录。 具体而言,位于 中的 AJAX 处理器在执行对 表的 UPDATE 操作时,仅依据攻击者提供的 主键进行定位,而未施加 的所有权约束。这使得任何具备 权限的用户都可以重新安排、抑制或更改其他用户所创建的已排期社交媒体帖子的发布状态。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Adenion | Blog2Social | 0 ~ 9.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89029 | 4.3 MEDIUM | Blog2Social WordPress Plugin < 9.1.0 User Enumeration via AJAX Handler |
| CVE-2026-89030 | 4.3 MEDIUM | Blog2Social WordPress Plugin < 9.1.0 User Email Disclosure via b2s_search_user |
No comments yet