Authorization Bypass in Nelio Content WordPress Plugin
An authorization bypass vulnerability in the Nelio Content WordPress plugin allows authenticated contributors to delete arbitrary reusable social messages.
CVE search metadata
CVE search record: CVE-2026-94505. Severity: high. CVSS: 8.1. KEV: no. Product: Nelio Content – Editorial Calendar & Social Media Auto-Posting (<= 4.5.0). Brief: Authorization Bypass in Nelio Content WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-nelio-auth-bypass/
The Nelio Content - Editorial Calendar & Social Media Auto-Posting plugin for WordPress is affected by an authorization bypass vulnerability (CVE-2026-94505) in all versions up to and including 4.5.0. The vulnerability stems from the plugin's failure to adequately verify user permissions before executing deletion actions on the nc_reusable_social post type.
An attacker with at least contributor-level access can leverage this flaw to permanently remove social media content authored by other users, including site administrators. This issue represents a significant integrity risk to content calendars and automated social media workflows managed via the plugin. Because the vulnerability exists within the application's authorization logic, it does not require additional software to exploit beyond standard authenticated access to the WordPress backend.
Impact
Successful exploitation results in the unauthorized, permanent deletion of reusable social media messages across the WordPress installation. This impact primarily affects marketing operations and editorial calendars, potentially causing significant disruption to social media campaigns and loss of prepared content. The vulnerability affects all users running Nelio Content versions 4.5.0 or older.
Recommendation
Prioritize the update of the Nelio Content plugin to the latest version. Monitor WordPress administrative access logs for unusual deletion activity associated with users assigned the 'contributor' role.
Threat Hunt
Monitor WordPress audit logs for deletion actions of 'nc_reusable_social' post types initiated by users with contributor roles
Data: WordPress plugin/application logs
Mitigations
Update Nelio Content plugin to the latest available version beyond 4.5.0
CVE-2026-94505