Extension WordPress
Vulnérabilités Blog2Social: Social Media Auto Post & Scheduler
Cette page rassemble les failles publiées pour Blog2Social: Social Media Auto Post & Scheduler, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Blog2Social: Social Media Auto Post & Scheduler
25 fiches
Blog2Social: Social Media Auto Post & Scheduler <= 8.9.2 – Unauthenticated Stored Cross-Site Scripting
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-8.9.2
8.9.3
25/06/2026
Blog2Social: Social Media Auto Post & Scheduler <= 8.9.0 – Missing Authorization to Authenticated (Subscriber+) Delete Arbitrary B2S Post Records via 'postId' Parameter
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 8.9.0. This is due to a missing ownership verification in the B2S_Post_Tools::deleteUserPublishPost() and B2S_Post_Tools::deleteUserSchedPost() functions,…
*-8.9.0
8.9.1
12/05/2026
Blog2Social: Social Media Auto Post & Scheduler <= 8.8.3 – Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Schedule Modification via 'b2s_id' Parameter
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through user-controlled key in all versions up to, and including, 8.8.3. This is due to the plugin's AJAX handlers failing to validate…
*-8.8.3
8.8.4
07/04/2026
Blog2Social: Social Media Auto Post & Scheduler <= 8.8.2 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Deletion via 'b2s_reset_social_meta_tags' AJAX Action
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized data loss in all versions up to, and including, 8.8.2. This is due to the resetSocialMetaTags() function only verifying that the user has…
*-8.8.2
8.8.3
25/03/2026
Blog2Social: Social Media Auto Post & Scheduler <= 8.7.4 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the b2s_curation_draft AJAX action in all versions up to, and including, 8.7.4. The…
*-8.7.4
8.7.5
17/02/2026
Blog2Social: Social Media Auto Post & Scheduler <= 8.7.2 – Incorrect Authorization to Authenticated (Subscriber+) Sensitive Information Exposure
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.7.2. This is due to a misconfigured authorization check on the 'getShipItemFullText' function which…
*-8.7.2
8.7.3
09/01/2026
Blog2Social <= 8.7.0 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Trashing
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'deleteUserCcDraftPost' function in all versions up to, and including, 8.7.0. This makes…
*-8.7.0
8.7.1
24/11/2025
Blog2Social: Social Media Auto Post & Scheduler <= 8.6.0 – Authenticated (Subscriber+) Blind Server-Side Request Forgery via post_url
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 8.6.0 via the getFullContent() function. This makes it possible for authenticated attackers, with Subscriber-level…
*-8.6.0
8.6.1
05/11/2025
Blog2Social: Social Media Auto Post & Scheduler <= 8.6.0 – Incorrect Authorization to Video File Upload
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an incorrect capability check on theuploadVideo() function in all versions up to, and including, 8.6.0. This makes it possible…
*-8.6.0
8.6.1
05/11/2025
Blog2Social <= 8.4.4 – Authenticated (Subscriber+) SQL Injection via `prgSortPostType` Parameter
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the ‘prgSortPostType’ parameter in all versions up to, and including, 8.4.4 due to insufficient escaping on the user supplied parameter and…
*-8.4.4
8.4.5
16/06/2025
Blog2Social: Social Media Auto Post & Scheduler <= 8.3.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.3.3 due to insufficient input sanitization and output escaping. This makes it possible for…
*-8.3.3
8.4.0
01/05/2025
Blog2Social: Social Media Auto Post & Scheduler <= 7.5.4 – Authenticated (Author+) Stored Cross-Site Scripting via File Upload
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 3gp2 file uploads in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This…
*-7.5.4
7.5.5
31/07/2024
Blog2Social: Social Media Auto Post & Scheduler <= 7.4.1 – Authenticated (Subscriber+) SQL Injection
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and…
*-7.4.1
7.4.2
10/06/2024
Blog2Social: Social Media Auto Post & Scheduler <= 7.4.2 – Information Exposure
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it possible for unauthenticated attackers to view limited information from password…
*-7.4.2
7.5.0
25/04/2024
Blog2Social: Social Media Auto Post & Scheduler <= 7.2.0 – Reflected Cross-Site Scripting
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'deletedPostsNumber' parameter in versions up to, and including, 7.2.0 due to insufficient input sanitization and output escaping. This makes…
[*, 7.2.1)
7.2.1
26/07/2023
Blog2Social <= 6.9.9 – Authenticated (Subscriber+) Server-Side Request Forgery
The Blog2Social plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 6.9.9 due to missing URL validation to ensure an external URL is used in the function b2sFileGetContents. This makes it possible…
*-6.9.9
6.9.10
03/10/2022
Blog2Social <= 6.9.9 – Authenticated (Subscriber+) SQL Injection
The Blog2Social plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.9.9 due to insufficient escaping on the user supplied parameter 'publish_error_code' and lack of sufficient preparation on the existing SQL query. This…
*-6.9.9
6.9.10
03/10/2022
Blog2Social <= 6.9.11 – Missing Authorization to Authenticated (Subscriber+) Settings Update
The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin…
*-6.9.11
6.9.12
27/09/2022
Blog2Social <= 6.9.3 – PHP Object Injection
The Blog2Social plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including 6.9.3 due to the use of unserialize on user supplied input retrieved from the 'b2s-post-meta-box-best-time-settings' and 'assignList' parameters.
*-6.9.3
6.9.4
05/04/2022
Blog2Social <= 6.8.6 – Reflected Cross-Site Scripting
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
*-6.8.6
6.8.7
22/11/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.