Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-89030

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Sep 16, 2026
Vendor unknown

Description

Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2s_search_user AJAX handler in includes/Ajax/Get.php invokes B2S_Tools::searchUser() in includes/Tools.php, which returns the email address of every matching user without restricting access to callers holding the list_users capability, allowing any user with the edit_posts capability to retrieve user email addresses including those of administrators.

References