Junglewise Threat Intelligence

CVE-2026-57648: Nelio Software Nelio Content broken access control

CVE-2026-57648 · Severity: medium · CVSS 4.3 · Published 2026-06-26

Executive brief

Nelio Content, a WordPress plugin used for managing editorial calendars and social media scheduling, contains a security flaw that allows users with low-level 'Contributor' permissions to perform actions they should not be authorized to do. While the impact is considered low, an attacker with a basic account could potentially interfere with content management workflows or settings. Organizations should update the plugin to version 4.3.5 to ensure proper access restrictions are enforced.

Technical details

A broken access control vulnerability exists in the Nelio Content plugin for WordPress (versions 4.3.4 and below) due to missing authorization checks (CWE-862). An attacker authenticated with Contributor-level privileges can exploit this flaw over the network without user interaction to perform actions typically reserved for higher-privileged roles. The vulnerability is classified as having low integrity impact and no confidentiality or availability impact. The issue is resolved in version 4.3.5.

Affected products

  • Nelio Software Nelio Content <= 4.3.4

Timeline

  • 2026-06-03: disclosed: Reported by Averon Averenkov
  • 2026-06-26: advisory: Published by Patchstack and NVD
  • 2026-06-26: patched: Version 4.3.5 released to address the issue

References

Related threats