CVE-2026-97227: NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credential Disclosure and Data Deletion
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials, delete arbitrary posts and reset the NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8's configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NextScripts: Social Networks Auto-Posterto a version that resolves this vulnerability.Fixed in 4.4.8
Event History
Frequently Asked Questions
Which users are realistically able to exploit this issue?
Users whom an administrator has granted access to the plugin's posting features can exploit the affected AJAX actions. The issue is not described as accessible to unauthenticated visitors.
What could an attacker do with successful exploitation?
An authorized posting-feature user could export configured social account credentials, delete arbitrary posts, and reset the plugin's configuration.
Are default WordPress users affected?
The available information indicates that exploitation requires access to the plugin's posting features granted by an administrator. It does not state that ordinary users without that access can exploit the issue.
How can an administrator assess exposure?
Check whether the site uses a version of NextScripts: Social Networks Auto-Poster earlier than 4.4.8 and identify users who have been granted its posting-feature access. Those users may have been able to access the vulnerable AJAX actions.