← WordPress Vulnerabilities
WordPress security by component

Blog2Social: Social Media Auto Post & Scheduler

Blog2Social: Social Media Auto Post & Scheduler is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Nov 06, 2025; the highest published CVSS base score is 4.3.

Plugin slug: blog2social-social-media-auto-post-scheduler

CVE-2025-12560: Blog2Social: Social Media Auto Post & Scheduler: Server-side request forgery

Blog2Social: Social Media Auto Post & Scheduler is affected by server-side request forgery. Exploitation requires an authenticated subscriber account. The vulnerable server can be induced to make attacker-selected network requests. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedNov 06, 2025
Safe version guidanceSee mitigation notes
Published vulnerabilities for blog2social-social-media-auto-post-scheduler
Safe version
Nov 06, 2025 CVE-2025-12560
Blog2Social: Social Media Auto Post & Scheduler: Server-side request forgery
Blog2Social: Social Media Auto Post & Scheduler is affected by server-side request forgery. Exploitation requires an authenticated subscriber account. The vulnerable server can be induced to make attacker-selected network requests. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVDPending
Nov 06, 2025 CVE-2025-12563
Blog2Social: Social Media Auto Post & Scheduler: A security weakness
Blog2Social: Social Media Auto Post & Scheduler is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVDPending