CVE-2025-4133: Blog2Social: Social Media Auto Post & Scheduler < 8.4.0 - Contributor+ Stored XSS
Published May 22, 2025
·Updated
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 8.4.0 does not escape the title of posts when outputting them in a dashboard, which could allow users with the contributor role to perform Cross-Site Scripting attacks.
Affected Software
2 affected components
Blog2Social Social Media Auto Post & Scheduler<8.4.0
Adenion Blog2social Wordpress<8.4.0
Event History
May 22, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-4133?
CVE-2025-4133 has a vulnerability severity rated as moderate, allowing for potential Cross-Site Scripting attacks.
2
How do I fix CVE-2025-4133?
To fix CVE-2025-4133, update the Blog2Social plugin to version 8.4.0 or later.
3
Who is affected by CVE-2025-4133?
Users with the contributor role in WordPress are affected by CVE-2025-4133.
4
What type of vulnerability is CVE-2025-4133?
CVE-2025-4133 is classified as a Cross-Site Scripting (XSS) vulnerability.
5
Which plugin is vulnerable in CVE-2025-4133?
The vulnerable plugin in CVE-2025-4133 is the Blog2Social: Social Media Auto Post & Scheduler.