CVE-2026-88931: Unknown Social Web Suite

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The Social Web Suite WordPress plugin through 4.1.12 does not restrict which of its settings may be written through an unauthenticated endpoint, allowing attackers to overwrite arbitrary Social Web Suite WordPress plugin through 4.1.12 options, including the shared secret that guards its own privileged endpoints.

Affected products

  • Unknown Social Web Suite: up to and including 4.1.12

Published 2026-10-09. Last modified 2026-10-09.