{"id":"CVE-2026-97227","title":"The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to it…","summary":"The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to it…","severity":"none","cwe":["CWE-862"],"product":"NextScripts: Social Networks Auto-Poster","affected":["nextscripts_social_networks_auto-poster < 4.4.8"],"published":"2026-09-27","updated":"2026-09-27","sourceUpdated":"2026-09-27T06:17:23.160","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97227","references":[{"url":"https://wpscan.com/vulnerability/df187bfb-47f1-4259-b955-3c676f3d8cc1/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-27T06:43:46.835Z","slug":"CVE-2026-97227","body":"## Overview\n\nThe NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials, delete arbitrary posts and reset the NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8's configuration.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}