What the vulnerability does
01Description
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform restricted actions that would be otherwise locked to a administrative-level user.
Explanation of Vulnerability in Simple Terms
02Summary
NextScripts: Social Networks Auto-Poster versions 4.3.17 and earlier contain an access control flaw that allows authenticated users to modify settings or data they should not have permission to change. The vulnerability requires a logged-in account but no additional user interaction. The impact is limited to integrity—an attacker cannot read sensitive data or disrupt service availability.
What an attacker can do
03Attacker Capabilities
Modify plugin settings or data beyond their assigned permissions.
Potential impact on your site
04Site Impact
Authenticated users could alter plugin configuration or content they shouldn't access, potentially disrupting social media posting workflows.
Conditions required to exploit
05Prerequisites
Attacker must have a valid login account on the site.
Key dates
06Disclosure timeline
October 16, 2024
CVE published
April 8, 2026
Record updated