Blog2Social <= 6.9.11 - Missing Authorization to Authenticated (Subscriber+) Settings Update
2022-09-27 00:00
Marco WotschkaStrategic Overview
StatusPatched in 6.9.12
Affected PluginBlog2Social: Social Media Auto Post & Scheduler
Affected Version
<= 6.9.11CVSS4.1Medium
CVE
CVE-2022-3622Vulnerability Overview
The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin settings intended to be modifiable by admins only.
Technical Analysis
REMEDIATION: Update to version 6.9.12, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C