CVE-2026-97227 PUBLISHED

NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credential Disclosure and Data Deletion

Assigner: WPScan
Reserved: 24.09.2026 Published: 27.09.2026 Updated: 27.09.2026

The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials, delete arbitrary posts and reset the NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8's configuration.

Product Status

Vendor Unknown
Product NextScripts: Social Networks Auto-Poster
Versions Default: unaffected
  • affected from 0 to 4.4.8 (excl.)

Credits

  • Dmitrii Ignatyev finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE