CVE-2026-88931 PUBLISHED

Social Web Suite <= 4.1.12 - Unauthenticated Arbitrary Plugin Settings Update

Assigner: WPScan
Reserved: 10.09.2026 Published: 09.10.2026 Updated: 09.10.2026

The Social Web Suite WordPress plugin through 4.1.12 does not restrict which of its settings may be written through an unauthenticated endpoint, allowing attackers to overwrite arbitrary Social Web Suite WordPress plugin through 4.1.12 options, including the shared secret that guards its own privileged endpoints.

Product Status

Vendor Unknown
Product Social Web Suite
Versions Default: unknown
  • affected from 0 to 4.1.12 (incl.)

Credits

  • Naoki Kawahigashi finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE