Skip to content
Threat Feed
high advisory

Authorization Bypass in Nelio Content WordPress Plugin

An authorization bypass vulnerability in the Nelio Content WordPress plugin allows authenticated contributors to delete arbitrary reusable social messages.

CVE search metadata

CVE search record: CVE-2026-94505. Severity: high. CVSS: 8.1. KEV: no. Product: Nelio Content – Editorial Calendar & Social Media Auto-Posting (<= 4.5.0). Brief: Authorization Bypass in Nelio Content WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-nelio-auth-bypass/

The Nelio Content - Editorial Calendar & Social Media Auto-Posting plugin for WordPress is affected by an authorization bypass vulnerability (CVE-2026-94505) in all versions up to and including 4.5.0. The vulnerability stems from the plugin's failure to adequately verify user permissions before executing deletion actions on the nc_reusable_social post type.

An attacker with at least contributor-level access can leverage this flaw to permanently remove social media content authored by other users, including site administrators. This issue represents a significant integrity risk to content calendars and automated social media workflows managed via the plugin. Because the vulnerability exists within the application's authorization logic, it does not require additional software to exploit beyond standard authenticated access to the WordPress backend.

Impact

Successful exploitation results in the unauthorized, permanent deletion of reusable social media messages across the WordPress installation. This impact primarily affects marketing operations and editorial calendars, potentially causing significant disruption to social media campaigns and loss of prepared content. The vulnerability affects all users running Nelio Content versions 4.5.0 or older.

Recommendation

Prioritize the update of the Nelio Content plugin to the latest version. Monitor WordPress administrative access logs for unusual deletion activity associated with users assigned the 'contributor' role.

Threat Hunt

Monitor WordPress audit logs for deletion actions of 'nc_reusable_social' post types initiated by users with contributor roles

T1068 medium medium confidence hunt now

Data: WordPress plugin/application logs

Mitigations

Update Nelio Content plugin to the latest available version beyond 4.5.0

immediate IT Operations

CVE-2026-94505