5.3
CVE-2026-89029
- EPSS 0.27%
- Veröffentlicht 16.09.2026 13:59:48
- Zuletzt bearbeitet 24.09.2026 21:08:55
- Erkennungen
Blog2Social WordPress Plugin < 9.1.0 User Enumeration via AJAX Handler
Blog2Social: Social Media Auto Post & Scheduler <= 9.0.0 - Authenticated (Subscriber+) Username Enumeration
Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs supplied in the owner parameter to display names without verifying that the caller is authorized to read user account data, allowing any user with the edit_posts capability to map WordPress user IDs to display names and confirm account existence for arbitrary IDs.
Mögliche Gegenmaßnahme
Blog2Social: Social Media Auto Post & Scheduler: Update to version 9.1.0, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerAdenion
≫
Produkt
Blog2Social
Default Statusunaffected
Version
0
Version <
9.1.0
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Blog2Social: Social Media Auto Post & Scheduler
Version
*-9.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.193 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 5.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://wordpress.org/plugins/blog2social/#developers
https://www.vulncheck.com/advisories/blog2social-wordpress-plugin-user-enumeration-via-ajax-handler
https://www.wordfence.com/threat-intel/vulnerabilities/id/6074ebd7-d44b-442f-bdef-532ddd865856