Twitter Posts to Blog WordPress Plugin Missing Authorization Vulnerability

Vulnerability

A vulnerability exists in the Twitter Posts to Blog plugin for WordPress, affecting all versions up to and including 1.11.25. The issue arises from a lack of proper capability checks in the 'dg_tw_options' function, allowing unauthorized users to modify plugin settings. This includes the ability to change Twitter API credentials, post author, post status, and the permissions required to access the plugin's admin menu.

Impact

Exploitation of this vulnerability allows for unauthorized users to modify plugin settings, potentially leading to unauthorized access or manipulation of WordPress posts through the plugin.

Reproduction

The vulnerability can be reproduced by sending a request to the 'dg_tw_options' function without the necessary authorization. This can be done by an unauthenticated user, who can then modify various plugin settings, including Twitter API credentials and post-related options.

Remediation

No known patch is available. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.

Added: Feb 11, 2026, 9:26 AM
Updated: Feb 11, 2026, 4:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.4
remediation
0.0
relevance
2.7
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.