Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-30783 | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform restricted actions that would be otherwise locked to a administrative-level user. |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 07 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nextscripts
Nextscripts social Networks Auto Poster |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:nextscripts:social_networks_auto_poster:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Nextscripts
Nextscripts social Networks Auto Poster |
Wed, 16 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Oct 2024 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform restricted actions that would be otherwise locked to a administrative-level user. | |
| Title | NextScripts: Social Networks Auto-Poster <= 4.3.17 - Missing Authorization | |
| Weaknesses | CWE-284 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:46:16.033Z
Reserved: 2024-10-15T17:56:10.608Z
Link: CVE-2020-36831
Updated: 2024-10-16T15:31:25.966Z
Status : Analyzed
Published: 2024-10-16T07:15:07.280
Modified: 2025-02-07T17:51:43.920
Link: CVE-2020-36831
No data.
OpenCVE Enrichment
No data.
EUVD