WordPress 插件 Blog2Social: Social Media Auto Post & Scheduler 在所有版本(包括 9.1.0 及以下版本)中存在授权绕过漏洞。该漏洞源于插件未正确验证用户是否具备执行特定操作的权限。因此,具有贡献者(Contributor)及以上权限的已认证攻击者可以查看、修改或删除其他用户的 Blog2Social 记录,包括泄露其他用户的网络认证标识和已排期的帖子内容;覆写其无权拥有的帖子上的 Open Graph 和 Twitter Card 帖子元数据;重新绑定其他
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pr-gateway | Blog2Social: Social Media Auto Post & Scheduler | ≤ 9.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pr-gateway | Blog2Social: Social Media Auto Post & Scheduler | 0 ~ 9.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet