Home/Product/adenion blog2social
Product

adenion blog2social

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-4133
< 8.4.0
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 8.4.0 does not escape the title of posts when outputti
5.4MEDIUM
CVE-2024-7302
< 7.5.5
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 3gp2 fil
6.4MEDIUM
CVE-2024-3549
< 7.4.2
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType'
9.9CRITICAL
CVE-2024-3678
< 7.5.0
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve
5.3MEDIUM
CVE-2022-3622
<= 6.9.11
The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, an
4.1MEDIUM
CVE-2023-40554
<= 7.2.0
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blog2Social, Adenion Blog2Social: Social Media Auto Post & Scheduler
7.1HIGH
CVE-2023-3936
< 7.2.1
The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, lead
6.1MEDIUM
CVE-2022-3247
< 6.9.10
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJAX action,
6.5MEDIUM
CVE-2022-3246
< 6.9.10
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape a paramet
8.8HIGH
CVE-2021-24956
< 6.8.7
The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate p
6.1MEDIUM
CVE-2021-24137
< 6.3.1
Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature,
8.8HIGH
CVE-2019-17550
< 5.9.0
The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to
6.1MEDIUM
CVE-2019-13572
<= 5.5.0
The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.
9.8CRITICAL
CVE-2019-9576
< 5.0.3
The Blog2Social plugin before 5.0.3 for WordPress allows wp-admin/admin.php?page=blog2social-ship XSS.
6.1MEDIUM
threatengine.sh