Executive brief
Blog2Social is a WordPress plugin used to automate social media scheduling and sharing. A security vulnerability in versions 8.9.2 and earlier allows unauthenticated attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could redirect users to malicious sites, display unauthorized advertisements, or potentially compromise user sessions.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Adenion Blog2Social plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a user's browser session. Exploitation requires a victim to perform an action, such as clicking a malicious link (User Interaction: Required). This can lead to unauthorized access to session tokens or the injection of malicious HTML payloads. The issue is resolved in version 8.9.3.
Affected products
- Adenion Blog2Social <= 8.9.2
Timeline
- 2026-05-21: other: Vulnerability reported by researcher João Pedro S Alcântara
- 2026-06-25: advisory: Patchstack advisory published
- 2026-06-26: disclosed: CVE published to NVD dataset
- 2026-06-26: patched: Patch available in version 8.9.3