SecAlerts
b

blog2social

Security Risk Profile

21
/100
low

Security Risk Score

Comprehensive risk assessment based on 11 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 26, 2024 to present

11
Total CVEs
1
Critical+High
0
Exploited
0
Unpatched

Threat Assessment

Avg CVSS
5.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
21/100
low
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
1
High
0
Medium
10
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
5

Age Distribution

Common Weaknesses (CWE)

1
SQL Injection
2
2
XSS
2
3
SSRF
1

Most Affected Products

1. Blog2Social Social Media Auto Post & Scheduler7
2. Adenion Blog2social Wordpress4
3. Blog2Social Blog2Social: Social Media Auto Post & Scheduler3
4. Blog2Social WordPress plugin1

Recent Vulnerabilities

See more →
CVE-2026-92829
CVSS 4.3medium

Blog2Social: Social Media Auto Post & Scheduler <= 9.1.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via Multiple AJAX Handlers

Sep 25, 2026🔧 No Patch
CVE-2026-4330
CVSS 4.3EPSS 0%medium

Blog2Social: Social Media Auto Post & Scheduler <= 8.8.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Schedule Modification via 'b2s_id' Parameter

Apr 8, 2026🔧 No Patch
CVE-2026-4331
CVSS 4.3EPSS 0%medium

Blog2Social: Social Media Auto Post & Scheduler <= 8.8.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Deletion via 'b2s_reset_social_meta_tags' AJAX Action

Mar 26, 2026🔧 No Patch
CVE-2025-13558
CVSS 5.4medium

Blog2Social <= 8.7.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Trashing

Nov 25, 2025🔧 No Patch
CVE-2025-12560
CVSS 4.3medium

Blog2Social: Social Media Auto Post & Scheduler <= 8.6.0 - Authenticated (Subscriber+) Blind Server-Side Request Forgery via post_url

Nov 6, 2025🔧 No Patch
CVE-2025-12563
CVSS 4.3medium

Blog2Social: Social Media Auto Post & Scheduler <= 8.6.0 - Incorrect Authorization to Video File Upload

Nov 6, 2025🔧 No Patch
CVE-2025-5673
CVSS 6.5EPSS 0%medium

Blog2Social <= 8.4.4 - Authenticated (Subscriber+) SQL Injection via `prgSortPostType` Parameter

Jun 17, 2025🔧 No Patch
CVE-2025-4133
CVSS 5.4medium

Blog2Social: Social Media Auto Post & Scheduler < 8.4.0 - Contributor+ Stored XSS

May 22, 2025🔧 No Patch
CVE-2024-7302
CVSS 6.4EPSS 0%medium

Blog2Social: Social Media Auto Post & Scheduler <= 7.5.4 - Authenticated (Author+) Stored Cross-Site Scripting via File Upload

Aug 1, 2024
CVE-2024-3549
CVSS 9.9critical

Blog2Social: Social Media Auto Post & Scheduler <= 7.4.1 - Authenticated (Subscriber+) SQL Injection

Jun 11, 2024

Monitor blog2social in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.