MEDIUM
Adenion
CVE published 2026-09-16
CVE-2026-89031
The Adenion Blog2Social plugin for WordPress before version 9.1.0 allows low-privileged users to modify scheduled post records of other users due to a lack of ownership constraints in the b2s_calendar_move_post AJAX handler. This vulnerability can disrupt social media posting schedules and content. WordPress site administrators and security teams should assess exposure and apply patches to prevent low-pri [truncated]