Blog2Social Missing Authorization Vulnerability Allows Deletion of Arbitrary Post Records

Vulnerability

A vulnerability exists in the Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress, affecting all versions through 8.9.0. The issue stems from a lack of proper authorization checks in the 'deleteUserPublishPost' and 'deleteUserSchedPost' functions. These functions fail to verify post ownership, enabling authenticated attackers to delete any user's B2S post records by sending specific post ID values through the 'postId' parameter. This vulnerability disrupts the content publishing process by allowing the deletion of scheduled and published social media posts from other users.

Impact

Exploitation of this vulnerability allows authenticated users to delete published and scheduled social media post records of other users, disrupting their content publishing workflows.

Reproduction

To reproduce this vulnerability, an authenticated user (with subscriber privileges) can send a request to the WordPress site with an arbitrary post ID value in the 'postId' parameter. The request will be processed by the vulnerable 'deleteUserPublishPost' or 'deleteUserSchedPost' functions, which will delete the specified post record without verifying the user's ownership of the post.

Remediation

Users are advised to update the Blog2Social: Social Media Auto Post & Scheduler plugin to version 8.9.1 or later.

Added: May 13, 2026, 4:53 PM
Updated: May 13, 2026, 4:53 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
6.4
remediation
7.7
relevance
8.3
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.