Blog2Social: Social Media Auto Post & Scheduler <= 8.7.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification
Blog2Social: Social Media Auto Post & Scheduler
Minimum safe version
8.8.4
Update to 8.8.4 or later to address 28 fixable vulnerabilities
Blog2Social: Social Media Auto Post & Scheduler <= 8.8.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Deletion via 'b2s_reset_social_meta_tags' AJAX Action
Blog2Social: Social Media Auto Post & Scheduler <= 8.8.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Schedule Modification via 'b2s_id' Parameter
CVE-2025-14943
CVE-2025-13558
CVE-2025-12563
CVE-2025-12560
Blog2Social <= 8.4.4 - Authenticated (Subscriber+) SQL Injection via `prgSortPostType` Parameter
WordPress Blog2Social Plugin < 8.4.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-7302
CVE-2024-3549
CVE-2024-3678
CVE-2023-40554
CVE-2023-3936
Blog2Social: Social Media Auto Post & Scheduler <= 7.2.0 - Reflected Cross-Site Scripting
Blog2Social: Social Media Auto Post & Scheduler < 5.0.1 - PHP Object Injection
Blog2Social <= 6.9.3 - PHP Object Injection
CVE-2022-3622
Blog2Social <= 5.0.0 - PHP Obj Injection
CVE-2022-3246
CVE-2022-3247
WordPress Blog2Social plugin <= 5.5.0 - SQL Injection (SQLi) vulnerability
WordPress Blog2Social plugin <= 6.3.0 - Authenticated SQL Injection (SQLi) vulnerability
Blog2Social: Social Media Auto Post & Scheduler <= 5.0.2 - Reflected Cross-Site Scripting
CVE-2019-13572
WordPress Blog2Social plugin <=5.8.1 - Cross-Site Scripting (XSS) vulnerability
CVE-2021-24137
CVE-2021-24956