CVE-2026-89030: Blog2Social WordPress Plugin < 9.1.0 User Email Disclosure via b2s_search_user

Published Sep 16, 2026
·
Updated

Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2ssearchuser AJAX handler in includes/Ajax/Get.php invokes B2STools::searchUser() in includes/Tools.php, which returns the email address of every matching user without restricting access to callers holding the listusers capability, allowing any user with the editposts capability to retrieve user email addresses including those of administrators.

Affected Software

1 affected component
WordPress Plugin Blog2Social<9.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WordPress Blog2Social (Adenion) plugin to a version that resolves this vulnerability.

    Fixed in 9.1.0

Event History

Sep 16, 2026
CVE Published
via MITRE·02:01 PM
Data Sourced
via MITRE·02:01 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated WordPress user account with the edit_posts capability can query the affected AJAX handler. This includes low-privileged users that can create or edit posts, and the exposed results can include administrator email addresses.

2

What information can an attacker obtain?

The affected user-search functionality returns email addresses for matching registered WordPress users. The disclosure is limited to email addresses; the provided data does not indicate integrity or availability impact.

3

Is authentication required?

Yes. Exploitation requires a WordPress account with the edit_posts capability, reflected by the PR:L vector. No user interaction is required, and the handler is reachable over the network.

4

What should be done to remediate the issue?

Upgrade Blog2Social to version 9.1.0 or later. The affected versions are those before 9.1.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203