<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Nelio Content – Editorial Calendar &amp; Social Media Auto-Posting (&lt;= 4.5.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/nelio-content--editorial-calendar--social-media-auto-posting--4.5.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 08:54:41 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/nelio-content--editorial-calendar--social-media-auto-posting--4.5.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in Nelio Content WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-nelio-auth-bypass/</link><pubDate>Sat, 03 Oct 2026 08:54:41 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-nelio-auth-bypass/</guid><description>An authorization bypass vulnerability in the Nelio Content WordPress plugin allows authenticated contributors to delete arbitrary reusable social messages.</description><content:encoded><![CDATA[<p>The Nelio Content - Editorial Calendar &amp; Social Media Auto-Posting plugin for WordPress is affected by an authorization bypass vulnerability (CVE-2026-94505) in all versions up to and including 4.5.0. The vulnerability stems from the plugin's failure to adequately verify user permissions before executing deletion actions on the <code>nc_reusable_social</code> post type.</p>
<p>An attacker with at least contributor-level access can leverage this flaw to permanently remove social media content authored by other users, including site administrators. This issue represents a significant integrity risk to content calendars and automated social media workflows managed via the plugin. Because the vulnerability exists within the application's authorization logic, it does not require additional software to exploit beyond standard authenticated access to the WordPress backend.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the unauthorized, permanent deletion of reusable social media messages across the WordPress installation. This impact primarily affects marketing operations and editorial calendars, potentially causing significant disruption to social media campaigns and loss of prepared content. The vulnerability affects all users running Nelio Content versions 4.5.0 or older.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the update of the Nelio Content plugin to the latest version. Monitor WordPress administrative access logs for unusual deletion activity associated with users assigned the 'contributor' role.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>web-application</category></item></channel></rss>