Adenion

Blog2social

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 16.09.2026 14:03:03
  • Zuletzt bearbeitet 24.09.2026 21:08:55

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_posts table usin...

  • EPSS 0.27%
  • Veröffentlicht 16.09.2026 14:01:30
  • Zuletzt bearbeitet 24.09.2026 20:43:32

Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2s_search_user AJAX handler in includes/Ajax/Get.php invokes B2S_Tools::searchUser() in includes/Tool...

  • EPSS 0.27%
  • Veröffentlicht 16.09.2026 13:59:48
  • Zuletzt bearbeitet 24.09.2026 21:08:55

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs supplied in the owner parameter ...

  • EPSS 0.24%
  • Veröffentlicht 26.06.2026 14:52:42
  • Zuletzt bearbeitet 26.06.2026 18:17:02

Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 22.05.2025 06:15:57
  • Zuletzt bearbeitet 09.06.2025 20:13:53

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 8.4.0 does not escape the title of posts when outputting them in a dashboard, which could allow users with the contributor role to perform Cross-Site Scripting attacks.

  • EPSS 0.39%
  • Veröffentlicht 01.08.2024 07:15:03
  • Zuletzt bearbeitet 01.03.2025 02:14:17

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 3gp2 file uploads in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This m...

  • EPSS 0.52%
  • Veröffentlicht 11.06.2024 07:15:41
  • Zuletzt bearbeitet 08.04.2026 18:21:27

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and la...

  • EPSS 0.57%
  • Veröffentlicht 26.04.2024 08:15:13
  • Zuletzt bearbeitet 08.04.2026 17:18:47

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it possible for unauthenticated attackers to view limited information fro...

  • EPSS 0.6%
  • Veröffentlicht 20.10.2023 08:15:11
  • Zuletzt bearbeitet 08.04.2026 19:17:53

The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to...

  • EPSS 0.35%
  • Veröffentlicht 06.09.2023 09:15:08
  • Zuletzt bearbeitet 21.11.2024 08:19:42

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blog2Social, Adenion Blog2Social: Social Media Auto Post & Scheduler plugin <= 7.2.0 versions.