PatchSiren

nelio CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH nelio CVE published 2026-10-03

CVE-2026-94505

The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This vulnerability allows authenticated attackers with contributor-level access and above to permanently delete any reusable social message (nc_reusable_social post), including those authored by administrators or other privileged users.