Sceawere
Vulnerability Detail
CVE-2026-94505UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Nelio Content Authorization Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 3h ago
- Vendor
- nelio
- Product
- Nelio Content – Editorial Calendar & Social Media Auto-Posting
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently delete any reusable social message (nc_reusable_social post), including those authored by administrators or other privileged users.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-03T07:16:49.033Z",
"pubdate": "2026-10-03T07:16:49.033Z",
"executiveSummary": "The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is susceptible to an authorization bypass vulnerability affecting all versions up to and including 4.5.0.\nThe vulnerability is categorized as an improper authorization flaw, which allows authenticated users with at least Contributor-level privileges to perform unauthorized administrative actions.\nSpecifically, the flaw permits the permanent deletion of reusable social messages (nc_reusable_social custom post type) regardless of the original author or user permissions.\nThis represents a significant integrity risk to the affected WordPress installation, as it enables low-privileged users to maliciously modify or destroy content managed by higher-privileged users, including administrators.\nThe vulnerability originates from a failure in the plugin's internal request handling, which lacks sufficient capability checks or nonce verification when processing deletion requests for the nc_reusable_social post type.\nExploitation requires the attacker to possess an active WordPress session with a minimum role of Contributor.\nThe scope of the attack is limited to the deletion of specific plugin-related content and does not necessarily grant remote code execution or privilege escalation to full administrative access; however, the impact on business operations and content scheduling remains substantial.",
"technicalDetails": "The core vulnerability lies within the plugin's server-side logic responsible for handling requests associated with the nc_reusable_social custom post type. Analysis indicates that the plugin functions managing the deletion of these entities fail to implement proper access control checks or verify the user's authority to modify or delete specific records.\nIn WordPress, secure implementation of post management functionality requires verifying user capabilities via the current_user_can() function. This ensures that the user attempting the action possesses the appropriate permissions to manipulate the target resource. In the affected versions of Nelio Content, these verification checks are absent or insufficiently validated during the execution of the delete operation.\nThe attack flow proceeds as follows: 1) An authenticated user with Contributor-level access identifies the endpoint or hook responsible for triggering the removal of an nc_reusable_social post. 2) The attacker crafts a request, such as an AJAX call or a direct POST request, targeting the deletion function of the identified post type. 3) Because the server-side code fails to validate the user's authority to delete the specific resource, the backend processing logic proceeds to invoke the WordPress wp_delete_post() function or equivalent database modification routines. 4) The server confirms the action and returns a success response to the attacker, effectively removing the targeted content from the database.\nThe lack of proper nonce (number used once) verification further exacerbates this issue, as it permits attackers to construct and execute these requests easily. An attacker does not need to bypass CSRF protections as the function itself is inherently insecure regardless of the request origin validation, provided the user is authenticated.\nThe impact of this vulnerability is the unauthorized permanent destruction of social media content templates and scheduled reusable messages. By systematically deleting these items, an attacker can disrupt editorial workflows, compromise automated marketing campaigns, and cause significant data loss for the site owners. Because the deletion is permanent, the impact is immediate and requires administrative intervention, such as database restoration from backups, to remediate. The vulnerability is restricted to the context of the WordPress instance and requires an active, valid login, but it significantly undermines the integrity of content management within the plugin environment."
}