CVE-2025-13558: Blog2Social <= 8.7.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Trashing
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'deleteUserCcDraftPost' function in all versions up to, and including, 8.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the status of arbitrary posts to trash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13558?
CVE-2025-13558 is considered a moderate severity vulnerability due to unauthorized modification of data.
How do I fix CVE-2025-13558?
To fix CVE-2025-13558, update the Blog2Social: Social Media Auto Post & Scheduler plugin to version 8.7.1 or later.
What versions are affected by CVE-2025-13558?
CVE-2025-13558 affects all versions of the Blog2Social: Social Media Auto Post & Scheduler plugin up to and including version 8.7.0.
Can authenticated users exploit CVE-2025-13558?
Yes, authenticated users can exploit CVE-2025-13558 due to the missing capability check that allows unauthorized data modification.
What specific function has the vulnerability in CVE-2025-13558?
The vulnerability in CVE-2025-13558 is found in the 'deleteUserCcDraftPost' function.