PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94505 nelio CVE debrief

The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This vulnerability allows authenticated attackers with contributor-level access and above to permanently delete any reusable social message (nc_reusable_social post), including those authored by administrators or other privileged users.

Vendor
nelio
Product
Nelio Content – Editorial Calendar & Social Media Auto-Posting
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders responsible for WordPress installations with the Nelio Content plugin should assess exposure and prioritize verification and remediation of this vulnerability to prevent data loss and impact on social media content. This includes reviewing the plugin version, restricting access to authorized users, and monitoring for suspicious activity.

Why it matters

The Nelio Content plugin for WordPress is vulnerable to authorization bypass, allowing authenticated attackers to delete reusable social messages. Defenders should prioritize verification and remediation of this vulnerability to prevent data loss and impact on social media content.

  • Authenticated attackers with contributor-level access and above can permanently delete reusable social messages.
  • Deletion of reusable social messages can impact the integrity of social media content.
  • Verification of user authorization is necessary to prevent exploitation of this vulnerability.
  • Remediation priority is high due to the potential for data loss and impact on social media content.

Technical summary

The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass due to improper verification of user authorization. This allows authenticated attackers with contributor-level access and above to permanently delete any reusable social message (nc_reusable_social post), including those authored by administrators or other privileged users. The vulnerability was reported by [email protected] and is documented in the CVE Program record and the NVD vulnerability detail page.

Defensive priority

Defenders should prioritize verifying and updating the Nelio Content plugin to prevent exploitation of this authorization bypass vulnerability.

Recommended defensive actions

  • Verify and update the Nelio Content plugin to the latest version.
  • Restrict access to the plugin's functionality to authorized users only.
  • Monitor for suspicious activity related to reusable social messages.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability was reported by [email protected] and is documented in the CVE Program record and the NVD vulnerability detail page. The Nelio Content plugin for WordPress is vulnerable to authorization bypass, allowing authenticated attackers to delete reusable social messages. This issue was confirmed in versions up to, and including, 4.5.0. Defenders should verify the plugin version and prioritize remediation to prevent data loss and impact on social media content.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94505 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94505

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94505 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94505

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/nelio-content/tags/4.5.0/includes/post-types/reusable-messages/class-nelio-content-reusable-message-rest-controller.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/nelio-content/tags/4.5.0/includes/utils/functions/helpers.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/changeset/3724505/nelio-content/tags/4.5.1

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.