The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an incorrect capability check on theuploadVideo() function in all versions up to, and including, 8.6.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload mp4 files to the 'wp-content/uploads/<YYYY>/<MM>/' directory.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Nov 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Blog2social
Blog2social blog2social Wordpress Wordpress wordpress |
|
| Vendors & Products |
Blog2social
Blog2social blog2social Wordpress Wordpress wordpress |
Thu, 06 Nov 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an incorrect capability check on theuploadVideo() function in all versions up to, and including, 8.6.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload mp4 files to the 'wp-content/uploads/<YYYY>/<MM>/' directory. | |
| Title | Blog2Social: Social Media Auto Post & Scheduler <= 8.6.0 - Incorrect Authorization to Video File Upload | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-11-06T04:36:21.892Z
Reserved: 2025-10-31T19:07:24.936Z
Link: CVE-2025-12563
No data.
Status : Received
Published: 2025-11-06T05:16:05.130
Modified: 2025-11-06T05:16:05.130
Link: CVE-2025-12563
No data.