---
id: CVE-2026-88931
title: >-
  The Social Web Suite  WordPress plugin through 4.1.12 does not restrict which
  of its settings may be written through an unauthenticated endpoint, allowing
  attackers to overwrite arbitrary Social Web Suite  WordPress plugin through
  4.1.12…
summary: >-
  The Social Web Suite  WordPress plugin through 4.1.12 does not restrict which
  of its settings may be written through an unauthenticated endpoint, allowing
  attackers to overwrite arbitrary Social Web Suite  WordPress plugin through
  4.1.12…
severity: none
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T07:17:18.950'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88931'
references:
  - url: 'https://wpscan.com/vulnerability/e1341110-abad-47f5-aed5-1c06cb0c8071/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-10-09T07:28:22.267Z'
---

## Overview

The Social Web Suite  WordPress plugin through 4.1.12 does not restrict which of its settings may be written through an unauthenticated endpoint, allowing attackers to overwrite arbitrary Social Web Suite  WordPress plugin through 4.1.12 options, including the shared secret that guards its own privileged endpoints.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
