Executive brief
Nelio Content, a WordPress plugin used for managing editorial calendars and social media scheduling, contains a security flaw that allows users with low-level 'Contributor' permissions to perform actions they should not be authorized to do. While the impact is considered low, an attacker with a basic account could potentially interfere with content management workflows or settings. Organizations should update the plugin to version 4.3.5 to ensure proper access restrictions are enforced.
Technical details
A broken access control vulnerability exists in the Nelio Content plugin for WordPress (versions 4.3.4 and below) due to missing authorization checks (CWE-862). An attacker authenticated with Contributor-level privileges can exploit this flaw over the network without user interaction to perform actions typically reserved for higher-privileged roles. The vulnerability is classified as having low integrity impact and no confidentiality or availability impact. The issue is resolved in version 4.3.5.
Affected products
- Nelio Software Nelio Content <= 4.3.4
Timeline
- 2026-06-03: disclosed: Reported by Averon Averenkov
- 2026-06-26: advisory: Published by Patchstack and NVD
- 2026-06-26: patched: Version 4.3.5 released to address the issue