VendorsAdenionblog2socialany version
Vulnerabilities

Adenion Blog2Social any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2024-3549
Blog2Social: Social Media Auto Post & Scheduler <= 7.4.1 - Authenticated (Subscriber+) SQL Injection
Published 2024-06-11 · Modified
9.9EPSS 0.005
CVE-2019-13572
The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.
Published 2019-08-01 · Modified
9.8EPSS 0.022
CVE-2021-24137
Blog2Social: Social Media Auto Post & Scheduler < 6.3.1 - Authenticated SQL Injection
Published 2021-03-18 · Modified
8.8EPSS 0.015
CVE-2022-3246
Blog2Social < 6.9.10 - Subscriber+ SQLi
Published 2022-10-25 · Modified
8.8EPSS 0.011
CVE-2023-40554
WordPress Blog2Social Plugin <= 7.2.0 is vulnerable to Cross Site Scripting (XSS)
Published 2023-09-06 · Modified
7.1EPSS 0.004
CVE-2022-3247
Blog2Social < 6.9.10 - Subscriber+ SSRF
Published 2022-10-25 · Modified
6.5EPSS 0.007
CVE-2024-7302
Blog2Social: Social Media Auto Post & Scheduler <= 7.5.4 - Authenticated (Author+) Stored Cross-Site Scripting via File Upload
Published 2024-08-01 · Analyzed
6.4EPSS 0.004
CVE-2021-24956
Blog2Social < 6.8.7 - Reflected Cross-Site Scripting
Published 2021-12-21 · Modified
6.1EPSS 0.014
CVE-2019-9576
The Blog2Social plugin before 5.0.3 for WordPress allows wp-admin/admin.php?page=blog2social-ship XSS.
Published 2019-03-05 · Modified
6.1EPSS 0.014
CVE-2019-17550
The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the b2s_id parameter. The component is: views/b2s/post.calendar.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.
Published 2019-11-13 · Modified
6.1EPSS 0.013
CVE-2023-3936
Blog2Social < 7.2.1 - Reflected XSS
Published 2023-08-21 · Modified
6.1EPSS 0.009
CVE-2025-4133
Blog2Social: Social Media Auto Post & Scheduler < 8.4.0 - Contributor+ Stored XSS
Published 2025-05-22 · Analyzed
5.4EPSS 0.003
CVE-2024-3678
Blog2Social: Social Media Auto Post & Scheduler <= 7.4.2 - Information Exposure
Published 2024-04-26 · Modified
5.3EPSS 0.006
CVE-2022-3622
Blog2Social <= 6.9.11 - Missing Authorization to Authenticated (Subscriber+) Settings Update
Published 2023-10-20 · Modified
4.3EPSS 0.006