CVE-2019-17550: Adenion BLOG2SOCIAL

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the b2s_id parameter. The component is: views/b2s/post.calendar.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.

Affected products

  • Adenion BLOG2SOCIAL: before 5.9.0 (fixed in 5.9.0)

Published 2019-11-13. Last modified 2026-06-17.