plugin

Tweet Old Post Vulnerabilities

11 known security issues reported for the Tweet Old Post WordPress plugin. Most recent disclosed Oct 27, 2025.

1 high 3 medium

Running Tweet Old Post on your site? Check whether your installed version is affected.

Scan your site free

Revive Social – Social Media Auto Post and Scheduling Automation Plugin [tweet-old-post] <= 9.3.3 (unfixed)

unknown

[en] Missing Authorization vulnerability in Codeinwp Revive Old Posts tweet-old-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Revive Old Posts: from n/a through <= 9.3.3.

Affected:
up to 9.3.3
Fix:
No patched version reported
Disclosed:
Oct 27, 2025

CVE-2025-62954 on NVD →

Revive Old Posts <= 9.3.3 - Missing Authorization

medium

The Revive Old Posts plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 9.3.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 9.3.3
Fixed in:
9.3.4
Disclosed:
Oct 14, 2025

CVE-2025-62954 on NVD →

ThemeIsle SDK <= Various Versions - Missing Authorization

medium

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to update options values that allow ThemeIsle to track...

CVSS:
5.3
Affected:
up to 9.0.25
Fixed in:
9.0.26
Disclosed:
Feb 1, 2024

CVE-2024-1047 on NVD →

Revive Social – Social Media Auto Post and Scheduling Automation Plugin [tweet-old-post] < 9.0.11

unknown

[en] The Revive Old Posts WordPress plugin before 9.0.11 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

Affected:
up to 9.0.11
Fixed in:
9.0.11
Disclosed:
Jan 30, 2023

CVE-2022-4680 on NVD →

Revive Old Posts <= 9.0.10 - Authenticated (Admin+) PHP Object Injection

medium

The Revive Old Posts plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 9.0.10 via deserialization of untrusted input in the vulnerable function 'is_set_not_empty'. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugi...

CVSS:
6.6
Affected:
up to 9.0.10
Fixed in:
9.0.11
Disclosed:
Jan 4, 2023

CVE-2022-4680 on NVD →

Revive Social – Social Media Auto Post and Scheduling Automation Plugin [tweet-old-post] < 6.9.4

unknown

Because of this vulnerability, the attackers can have an administrator account on the target's website. Upgrade the plugin.

Affected:
up to 6.9.4
Fixed in:
6.9.4
Disclosed:
May 15, 2015

Revive Old Posts – Social Media Auto Post and Scheduling Plugin < 8.0.0 - Authorization Bypass

high

The Revive Old Posts – Social Media Auto Post and Scheduling Plugin for WordPress is vulnerable to Authorization Bypass due to a missing capability check on the update_response AJAX action in versions before 8.0.0. This makes it possible for unauthenticated attackers to create a new account with administrative-level pr...

CVSS:
8.6
Affected:
up to 8.0.0
Fixed in:
8.0.0
Disclosed:
Feb 2, 2015

Revive Social – Social Media Auto Post and Scheduling Automation Plugin [tweet-old-post] < 8.0.0

unknown

The Revive Old Posts – Social Media Auto Post and Scheduling Plugin for WordPress is vulnerable to Authorization Bypass due to a missing capability check on the update_response AJAX action in versions before 8.0.0. This makes it possible for unauthenticated attackers to create a new account with administrative-level pr...

Affected:
up to 8.0.0
Fixed in:
8.0.0
Disclosed:
Feb 2, 2015

Revive Social – Social Media Auto Post and Scheduling Automation Plugin [tweet-old-post] < 3.2.6

unknown

Tweet Old Post plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Upgrade the plugin.

Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Sep 6, 2011

Revive Social – Social Media Auto Post and Scheduling Automation Plugin [tweet-old-post] < 6.9.4

unknown

Leveraging a publicly accessible AJAX function named &lsquo;update_response&rsquo;, it is possible to update any option with the WordPress installation. Using this vulnerability, it is possible to gain administrative access to the WordPress installation by updating the options &lsquo;default_role&rsquo; and &lsquo;user...

Affected:
up to 6.9.4
Fixed in:
6.9.4

Revive Social – Social Media Auto Post and Scheduling Automation Plugin [tweet-old-post] < 3.2.6

unknown
Affected:
up to 3.2.6
Fixed in:
3.2.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database