← WordPress Vulnerabilities
WordPress security by component

Blog2Social

Blog2Social is a WordPress component with 22 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest CVE/CNA score is 9.9.

Plugin slug: blog2social

CVE-2026-56044: Blog2Social: Cross-site scripting

Blog2Social is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 8.9.2.

PublishedJun 26, 2026
Known safe version8.9.3
Safe version
Jun 26, 2026 CVE-2026-56044
Blog2Social: Cross-site scripting
Blog2Social is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 8.9.2.
8.9.3
CVE7.1
NVDPending
May 13, 2026 CVE-2026-7051
Blog2Social: Social Media Auto Post & Scheduler: A security weakness
Blog2Social: Social Media Auto Post & Scheduler is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 8.9.0.
> 8.9.0
CVE5.4
NVDPending
Apr 08, 2026 CVE-2026-4330
Blog2Social: Social Media Auto Post & Scheduler: A security weakness
Blog2Social: Social Media Auto Post & Scheduler is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 8.8.3.
> 8.8.3
CVE4.3
NVDPending
Mar 26, 2026 CVE-2026-4331
Blog2Social: Social Media Auto Post & Scheduler: A security weakness
Blog2Social: Social Media Auto Post & Scheduler is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 8.8.2.
> 8.8.2
CVE4.3
NVDPending
Feb 18, 2026 CVE-2026-1942
Blog2Social: Social Media Auto Post & Scheduler: A security weakness
Blog2Social: Social Media Auto Post & Scheduler is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Jan 10, 2026 CVE-2025-14943
Blog2Social: Social Media Auto Post & Scheduler: Sensitive information exposure
Blog2Social: Social Media Auto Post & Scheduler is affected by sensitive information exposure. Exploitation requires at least subscriber-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVDPending
Nov 25, 2025 CVE-2025-13558
Blog2Social: Social Media Auto Post & Scheduler: A security weakness
Blog2Social: Social Media Auto Post & Scheduler is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Jun 17, 2025 CVE-2025-5673
Blog2Social: Social Media Auto Post & Scheduler: SQL injection
Blog2Social: Social Media Auto Post & Scheduler is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVDPending
May 22, 2025 CVE-2025-4133
Blog2Social: Social Media Auto Post & Scheduler: Cross-site scripting
Blog2Social: Social Media Auto Post & Scheduler is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Aug 01, 2024 CVE-2024-7302
Blog2Social: Social Media Auto Post & Scheduler: Cross-site scripting
Blog2Social: Social Media Auto Post & Scheduler is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jun 11, 2024 CVE-2024-3549
Blog2Social: Social Media Auto Post & Scheduler: SQL injection
Blog2Social: Social Media Auto Post & Scheduler is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.9
NVDPending
Apr 26, 2024 CVE-2024-3678
Blog2Social: Social Media Auto Post & Scheduler: Sensitive information exposure
Blog2Social: Social Media Auto Post & Scheduler is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Oct 20, 2023 CVE-2022-3622
Blog2Social: A security weakness
Blog2Social is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.1
NVD4.3
Sep 06, 2023 CVE-2023-40554
Blog2Social: Cross-site scripting
Blog2Social is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Aug 21, 2023 CVE-2023-3936
Blog2Social: Cross-site scripting
Blog2Social is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Oct 25, 2022 CVE-2022-3247
Blog2Social: Social Media Auto Post & Scheduler: Server-side request forgery
Blog2Social: Social Media Auto Post & Scheduler is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE6.5
NVD6.5
Oct 25, 2022 CVE-2022-3246
Blog2Social: Social Media Auto Post & Scheduler: SQL injection
Blog2Social: Social Media Auto Post & Scheduler is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
Dec 21, 2021 CVE-2021-24956
Blog2Social: Social Media Auto Post & Scheduler: Cross-site scripting
Blog2Social: Social Media Auto Post & Scheduler is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Mar 18, 2021 CVE-2021-24137
Blog2Social: SQL injection
Blog2Social is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
Nov 13, 2019 CVE-2019-17550
Blog2Social: Cross-site scripting
Blog2Social is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 01, 2019 CVE-2019-13572
Blog2Social: SQL injection
Blog2Social is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Mar 05, 2019 CVE-2019-9576
Blog2Social: Cross-site scripting
Blog2Social is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1