CVE-2020-36831: Nextscripts Social Networks Auto Poster

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform restricted actions that would be otherwise locked to a administrative-level user.

Affected products

  • Nextscripts Social Networks Auto Poster: before 4.3.18 (fixed in 4.3.18)

Published 2024-10-16. Last modified 2026-06-17.