Sceawere
Vulnerability Detail
CVE-2026-97227UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
NextScripts SNAP Broken Access Control
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.9
- Creation Date
- 1d ago
- Vendor
- Unknown
- Product
- NextScripts: Social Networks Auto-Poster
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials, delete arbitrary posts and reset the NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8's configuration.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.9",
"pubDate": "2026-09-27T06:17:23.160Z",
"pubdate": "2026-09-27T06:17:23.160Z",
"executiveSummary": "The NextScripts: Social Networks Auto-Poster plugin for WordPress, in versions prior to 4.4.8, suffers from a critical Broken Access Control vulnerability. The flaw stems from insufficient authorization checks within several AJAX action handlers, which rely exclusively on nonce validation rather than proper capability checks (e.g., current_user_can).\nThis vulnerability allows authenticated users, specifically those granted limited posting privileges by an administrator, to perform unauthorized administrative operations. By bypassing intended permission boundaries, an attacker can extract sensitive social media account credentials, delete arbitrary posts, or perform a full reset of the plugin configuration.\nThe risk is categorized as high, as it grants privilege escalation within the context of the plugin’s functionality. Exploitation requires the attacker to possess an active session with valid, albeit limited, WordPress user credentials. The primary impact involves the compromise of social media integration security, potential data loss via post deletion, and the disruption of site services through configuration reset.",
"technicalDetails": "The vulnerability is rooted in the implementation of the plugin's AJAX handler architecture, specifically regarding the handling of sensitive administrative requests. In versions prior to 4.4.8, the plugin implemented server-side request processing that failed to enforce robust WordPress capability checks. While the handlers performed a check for a security nonce to prevent Cross-Site Request Forgery (CSRF), they lacked an authorization check to verify if the user initiating the request possessed the necessary administrative privileges required for high-impact actions.\nThe attack flow follows a predictable pattern of authorization bypass. Because the plugin logic assumes that the presence of a valid nonce is sufficient for trust, an authenticated user—even one with lower-level privileges like 'Contributor' or 'Author' who has been granted plugin-specific posting access—can successfully invoke AJAX functions intended only for site administrators.\nThe exploitation process occurs as follows: 1) The attacker identifies the AJAX action endpoints used by the NextScripts: Social Networks Auto-Poster plugin. 2) The attacker obtains a valid security nonce, which is typically accessible to any authenticated user through the plugin's settings or posting interfaces. 3) The attacker crafts an HTTP POST request targeting the admin-ajax.php file, including the required 'action' parameter and the harvested nonce. 4) The server-side code validates the nonce, finds it correct, and proceeds to execute the requested administrative function without verifying the user's role or capabilities.\nSpecific actions reachable via this flaw include the extraction of sensitive data, such as decrypted or plaintext social network credentials configured within the plugin. Additionally, the attacker can invoke functions to wipe the database of posts or trigger a 'reset' function that clears the plugin's configuration, effectively performing a Denial of Service (DoS) on the social auto-posting functionality. The absence of explicit user capability checks in the AJAX action functions is the primary technical deficiency that facilitates this improper authorization state. This vulnerability remains persistent until the update to version 4.4.8, where the developers introduced explicit verification of user roles before executing administrative routines."
}