CVE-2026-97277: WordPress Social Boost plugin <= 3.6.2 - Broken Access Control vulnerability
Published Oct 1, 2026
·Updated
Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.
Affected Software
1 affected component
WordPress Social Boost plugin<=3.6.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Social Boost pluginto a version that resolves this vulnerability.Fixed in 3.7.0
Event History
Oct 1, 2026
CVE Published
via MITRE·02:34 PM
Data Sourced
via MITRE·02:34 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which users could exploit this issue?
The available information identifies subscribers as the affected privilege level. Exploitation requires an authenticated account with subscriber access.
2
What is the likely impact of successful exploitation?
The supplied CVSS vector indicates high confidentiality impact and low integrity and availability impact. The issue is remotely reachable, has low attack complexity, requires low privileges, and does not require user interaction.