CVE-2020-36831: NextScripts: Social Networks Auto-Poster <= 4.3.17 - Missing Authorization
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform restricted actions that would be otherwise locked to a administrative-level user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36831?
CVE-2020-36831 has a medium severity rating due to the potential for low-privileged attackers to bypass authorization controls.
How do I fix CVE-2020-36831?
To fix CVE-2020-36831, update the NextScripts Social Networks Auto-Poster plugin to version 4.3.18 or later.
Which versions are affected by CVE-2020-36831?
CVE-2020-36831 affects all versions of the NextScripts Social Networks Auto-Poster plugin up to and including 4.3.17.
What type of vulnerability is CVE-2020-36831?
CVE-2020-36831 is an authorization bypass vulnerability due to missing capability checks.
Who is impacted by CVE-2020-36831?
Website administrators using vulnerable versions of the NextScripts Social Networks Auto-Poster plugin are impacted by CVE-2020-36831.