plugin

Blog2Social Vulnerabilities

51 known security issues reported for the Blog2Social WordPress plugin. Most recent disclosed Jun 25, 2026.

2 critical 5 high 19 medium

Running Blog2Social on your site? Check whether your installed version is affected.

Scan your site free

Blog2Social: Social Media Auto Post & Scheduler <= 8.9.2 - Unauthenticated Stored Cross-Site Scripting

high

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wil...

CVSS:
7.2
Affected:
up to 8.9.2
Fixed in:
8.9.3
Disclosed:
Jun 25, 2026

CVE-2026-56044 on NVD →

Blog2Social: Social Media Auto Post & Scheduler <= 8.9.0 - Missing Authorization to Authenticated (Subscriber+) Delete Arbitrary B2S Post Records via 'postId' Parameter

medium

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 8.9.0. This is due to a missing ownership verification in the B2S_Post_Tools::deleteUserPublishPost() and B2S_Post_Tools::deleteUserSchedPost() functions, neither functio...

CVSS:
5.4
Affected:
up to 8.9.0
Fixed in:
8.9.1
Disclosed:
May 12, 2026

CVE-2026-7051 on NVD →

Blog2Social: Social Media Auto Post & Scheduler <= 8.8.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Schedule Modification via 'b2s_id' Parameter

medium

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through user-controlled key in all versions up to, and including, 8.8.3. This is due to the plugin's AJAX handlers failing to validate that the user-supplied 'b2s_id' parameter belongs to the current user befo...

CVSS:
4.3
Affected:
up to 8.8.3
Fixed in:
8.8.4
Disclosed:
Apr 7, 2026

CVE-2026-4330 on NVD →

Blog2Social - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Deletion via 'b2s_reset_social_meta_tags' AJAX Action vulnerability

medium

Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Deletion via 'b2s_reset_social_meta_tags' AJAX Action vulnerability

CVSS:
4.3
Affected:
up to 8.8.2
Fixed in:
8.8.3
Disclosed:
Mar 27, 2026

Blog2Social: Social Media Auto Post & Scheduler <= 8.8.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Deletion via 'b2s_reset_social_meta_tags' AJAX Action

medium

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized data loss in all versions up to, and including, 8.8.2. This is due to the resetSocialMetaTags() function only verifying that the user has the 'read' capability and a valid b2s_security_nonce, both of which are availab...

CVSS:
4.3
Affected:
up to 8.8.2
Fixed in:
8.8.3
Disclosed:
Mar 25, 2026

CVE-2026-4331 on NVD →

Blog2Social: Social Media Auto Post & Scheduler <= 8.7.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification

medium

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the b2s_curation_draft AJAX action in all versions up to, and including, 8.7.4. The curationDraft() function only verifies current_user_can('read') without che...

CVSS:
6.5
Affected:
up to 8.7.4
Fixed in:
8.7.5
Disclosed:
Feb 17, 2026

CVE-2026-1942 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 8.7.3

unknown

[en] The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.7.2. This is due to a misconfigured authorization check on the 'getShipItemFullText' function which only verifies that a user has the 'read' capability (S...

Affected:
up to 8.7.3
Fixed in:
8.7.3
Disclosed:
Jan 10, 2026

CVE-2025-14943 on NVD →

Blog2Social: Social Media Auto Post & Scheduler <= 8.7.2 - Incorrect Authorization to Authenticated (Subscriber+) Sensitive Information Exposure

medium

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.7.2. This is due to a misconfigured authorization check on the 'getShipItemFullText' function which only verifies that a user has the 'read' capability (Subscr...

CVSS:
4.3
Affected:
up to 8.7.2
Fixed in:
8.7.3
Disclosed:
Jan 9, 2026

CVE-2025-14943 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 8.7.1

unknown

[en] The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'deleteUserCcDraftPost' function in all versions up to, and including, 8.7.0. This makes it possible for authenticated attackers, with Subscriber-leve...

Affected:
up to 8.7.1
Fixed in:
8.7.1
Disclosed:
Nov 25, 2025

CVE-2025-13558 on NVD →

Blog2Social <= 8.7.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Trashing

medium

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'deleteUserCcDraftPost' function in all versions up to, and including, 8.7.0. This makes it possible for authenticated attackers, with Subscriber-level acc...

CVSS:
5.4
Affected:
up to 8.7.0
Fixed in:
8.7.1
Disclosed:
Nov 24, 2025

CVE-2025-13558 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 8.6.1

unknown

[en] The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 8.6.0 via the getFullContent() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to ar...

Affected:
up to 8.6.1
Fixed in:
8.6.1
Disclosed:
Nov 6, 2025

CVE-2025-12560 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 8.6.1

unknown

[en] The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an incorrect capability check on theuploadVideo() function in all versions up to, and including, 8.6.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...

Affected:
up to 8.6.1
Fixed in:
8.6.1
Disclosed:
Nov 6, 2025

CVE-2025-12563 on NVD →

Blog2Social: Social Media Auto Post & Scheduler <= 8.6.0 - Authenticated (Subscriber+) Blind Server-Side Request Forgery via post_url

medium

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 8.6.0 via the getFullContent() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitra...

CVSS:
4.3
Affected:
up to 8.6.0
Fixed in:
8.6.1
Disclosed:
Nov 5, 2025

CVE-2025-12560 on NVD →

Blog2Social: Social Media Auto Post & Scheduler <= 8.6.0 - Incorrect Authorization to Video File Upload

medium

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an incorrect capability check on theuploadVideo() function in all versions up to, and including, 8.6.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to uplo...

CVSS:
4.3
Affected:
up to 8.6.0
Fixed in:
8.6.1
Disclosed:
Nov 5, 2025

CVE-2025-12563 on NVD →

Blog2Social <= 8.4.4 - Authenticated (Subscriber+) SQL Injection via `prgSortPostType` Parameter

medium

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the ‘prgSortPostType’ parameter in all versions up to, and including, 8.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...

CVSS:
6.5
Affected:
up to 8.4.4
Fixed in:
8.4.5
Disclosed:
Jun 16, 2025

CVE-2025-5673 on NVD →

Blog2Social: Social Media Auto Post & Scheduler <= 8.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 8.3.3
Fixed in:
8.4.0
Disclosed:
May 1, 2025

CVE-2025-4133 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 7.5.5

unknown

[en] The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 3gp2 file uploads in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level a...

Affected:
up to 7.5.5
Fixed in:
7.5.5
Disclosed:
Aug 1, 2024

CVE-2024-7302 on NVD →

Blog2Social: Social Media Auto Post & Scheduler <= 7.5.4 - Authenticated (Author+) Stored Cross-Site Scripting via File Upload

medium

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 3gp2 file uploads in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access...

CVSS:
6.4
Affected:
up to 7.5.4
Fixed in:
7.5.5
Disclosed:
Jul 31, 2024

CVE-2024-7302 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 7.4.2

unknown

[en] The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This mak...

Affected:
up to 7.4.2
Fixed in:
7.4.2
Disclosed:
Jun 11, 2024

CVE-2024-3549 on NVD →

Blog2Social: Social Media Auto Post & Scheduler <= 7.4.1 - Authenticated (Subscriber+) SQL Injection

critical

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...

CVSS:
9.9
Affected:
up to 7.4.1
Fixed in:
7.4.2
Disclosed:
Jun 10, 2024

CVE-2024-3549 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 7.5.0

unknown

[en] The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it possible for unauthenticated attackers to view limited information from password protected posts.

Affected:
up to 7.5.0
Fixed in:
7.5.0
Disclosed:
Apr 26, 2024

CVE-2024-3678 on NVD →

Blog2Social: Social Media Auto Post & Scheduler <= 7.4.2 - Information Exposure

medium

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it possible for unauthenticated attackers to view limited information from password protected posts.

CVSS:
5.3
Affected:
up to 7.4.2
Fixed in:
7.5.0
Disclosed:
Apr 25, 2024

CVE-2024-3678 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 6.9.12

unknown

[en] The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin settings intended to be modifiable by admins...

Affected:
up to 6.9.12
Fixed in:
6.9.12
Disclosed:
Oct 20, 2023

CVE-2022-3622 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 7.2.1

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blog2Social, Adenion Blog2Social: Social Media Auto Post & Scheduler plugin <= 7.2.0 versions.

Affected:
up to 7.2.1
Fixed in:
7.2.1
Disclosed:
Sep 6, 2023

CVE-2023-40554 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 7.2.1

unknown

[en] The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 7.2.1
Fixed in:
7.2.1
Disclosed:
Aug 21, 2023

CVE-2023-3936 on NVD →

Blog2Social: Social Media Auto Post & Scheduler <= 7.2.0 - Reflected Cross-Site Scripting

medium

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'deletedPostsNumber' parameter in versions up to, and including, 7.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...

CVSS:
6.1
Affected:
up to 7.2.1
Fixed in:
7.2.1
Disclosed:
Jul 26, 2023

CVE-2023-3936 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 7.2.1

unknown

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'deletedPostsNumber' parameter in versions up to, and including, 7.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...

Affected:
up to 7.2.1
Fixed in:
7.2.1
Disclosed:
Jul 26, 2023

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 6.9.10

unknown

[en] The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action, and does not ensure that the URL to make a request to is an external one. As a result, any authenticated users, such as subscriber could perform SSRF attacks

Affected:
up to 6.9.10
Fixed in:
6.9.10
Disclosed:
Oct 25, 2022

CVE-2022-3247 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 6.9.10

unknown

[en] The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscribers

Affected:
up to 6.9.10
Fixed in:
6.9.10
Disclosed:
Oct 25, 2022

CVE-2022-3246 on NVD →

Blog2Social <= 6.9.9 - Authenticated (Subscriber+) SQL Injection

high

The Blog2Social plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.9.9 due to insufficient escaping on the user supplied parameter 'publish_error_code' and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-l...

CVSS:
8.8
Affected:
up to 6.9.9
Fixed in:
6.9.10
Disclosed:
Oct 3, 2022

CVE-2022-3246 on NVD →

Blog2Social <= 6.9.9 - Authenticated (Subscriber+) Server-Side Request Forgery

medium

The Blog2Social plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 6.9.9 due to missing URL validation to ensure an external URL is used in the function b2sFileGetContents. This makes it possible for authenticated users, with subscriber-level access or higher, to perfor...

CVSS:
6.8
Affected:
up to 6.9.9
Fixed in:
6.9.10
Disclosed:
Oct 3, 2022

CVE-2022-3247 on NVD →

Blog2Social <= 6.9.11 - Missing Authorization to Authenticated (Subscriber+) Settings Update

medium

The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin settings intended to be modifiable by admins only.

CVSS:
4.1
Affected:
up to 6.9.11
Fixed in:
6.9.12
Disclosed:
Sep 27, 2022

CVE-2022-3622 on NVD →

Blog2Social <= 6.9.3 - PHP Object Injection

high

The Blog2Social plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including 6.9.3 due to the use of unserialize on user supplied input retrieved from the 'b2s-post-meta-box-best-time-settings' and 'assignList' parameters.

CVSS:
8.5
Affected:
up to 6.9.3
Fixed in:
6.9.4
Disclosed:
Apr 5, 2022

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 6.9.4

unknown

The Blog2Social plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including 6.9.3 due to the use of unserialize on user supplied input retrieved from the 'b2s-post-meta-box-best-time-settings' and 'assignList' parameters.

Affected:
up to 6.9.4
Fixed in:
6.9.4
Disclosed:
Apr 5, 2022

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 6.8.7

unknown

[en] The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 6.8.7
Fixed in:
6.8.7
Disclosed:
Dec 21, 2021

CVE-2021-24956 on NVD →

Blog2Social <= 6.8.6 - Reflected Cross-Site Scripting

medium

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 6.8.6
Fixed in:
6.8.7
Disclosed:
Nov 22, 2021

CVE-2021-24956 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 6.3.1

unknown

[en] Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary SQL commands.

Affected:
up to 6.3.1
Fixed in:
6.3.1
Disclosed:
Mar 18, 2021

CVE-2021-24137 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 6.3.1

unknown

Authenticated SQL Injection (SQLi) vulnerability found by Nguyen Anh Tien in WordPress Blog2Social plugin (versions <= 6.3.0).

Affected:
up to 6.3.1
Fixed in:
6.3.1
Disclosed:
Jun 9, 2020

Blog2Social: Social Media Auto Post & Scheduler <= 6.3.0 - Authenticated SQL Injection

high

Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary SQL commands.

CVSS:
8.8
Affected:
up to 6.3.0
Fixed in:
6.3.1
Disclosed:
May 29, 2020

CVE-2021-24137 on NVD →

Blog2Social: Social Media Auto Post & Scheduler < 5.9.0 - Reflected Cross-Site Scripting via b2s_id Parameter

medium

The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the b2s_id parameter. The component is: views/b2s/post.calendar.php. The attack vector is: When the Administrator is logged in, a reflected XS...

CVSS:
6.1
Affected:
up to 5.9.0
Fixed in:
5.9.0
Disclosed:
Nov 14, 2019

CVE-2019-17550 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 5.9.0

unknown

[en] The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the b2s_id parameter. The component is: views/b2s/post.calendar.php. The attack vector is: When the Administrator is logged in, a reflect...

Affected:
up to 5.9.0
Fixed in:
5.9.0
Disclosed:
Nov 13, 2019

CVE-2019-17550 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 5.6.0

unknown

[en] The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.

Affected:
up to 5.6.0
Fixed in:
5.6.0
Disclosed:
Aug 1, 2019

CVE-2019-13572 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 5.6.0

unknown

SQL Injection (SQLi) vulnerability found by Tin Duong in WordPress Blog2Social plugin (versions <= 5.5.0).

Affected:
up to 5.6.0
Fixed in:
5.6.0
Disclosed:
Jul 26, 2019

Blog2Social: Social Media Auto Post & Scheduler <= 5.5.0 - SQL Injection

critical

The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.

CVSS:
9.8
Affected:
up to 5.6.0
Fixed in:
5.6.0
Disclosed:
Jul 25, 2019

CVE-2019-13572 on NVD →

Blog2Social: Social Media Auto Post & Scheduler <= 5.0.2 - Reflected Cross-Site Scripting

medium

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘b2s_update_publish_date=' parameter in versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t...

CVSS:
6.1
Affected:
up to 5.0.3
Fixed in:
5.0.3
Disclosed:
May 2, 2019

CVE-2019-9576 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 5.0.3

unknown

[en] The Blog2Social plugin before 5.0.3 for WordPress allows wp-admin/admin.php?page=blog2social-ship XSS.

Affected:
up to 5.0.3
Fixed in:
5.0.3
Disclosed:
Mar 5, 2019

CVE-2019-9576 on NVD →

Blog2Social: Social Media Auto Post & Scheduler < 5.0.1 - PHP Object Injection

high

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.0.0 via deserialization of untrusted input in the vulnerable function named curationShare. This allows authenticated attackers to inject a PHP Object. No POP chain is presen...

CVSS:
7.4
Affected:
up to 5.0.1
Fixed in:
5.0.1
Disclosed:
Sep 21, 2018

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 5.0.1

unknown

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.0.0 via deserialization of untrusted input in the vulnerable function named curationShare. This allows authenticated attackers to inject a PHP Object. No POP chain is presen...

Affected:
up to 5.0.1
Fixed in:
5.0.1
Disclosed:
Sep 21, 2018

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 8.4.0

unknown
Affected:
up to 8.4.0
Fixed in:
8.4.0

CVE-2025-4133 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 8.4.5

unknown
Affected:
up to 8.4.5
Fixed in:
8.4.5

CVE-2025-5673 on NVD →

Blog2Social: Social Media Auto Post &amp; Scheduler [blog2social] < 5.0.1

unknown

The Blog2Social: Social Media Auto Post &amp; Scheduler WordPress plugin was affected by a PHP Obj Injection security vulnerability.

Affected:
up to 5.0.1
Fixed in:
5.0.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database