{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/nelio/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nelio:nelio_content:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-94505"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Nelio Content – Editorial Calendar \u0026 Social Media Auto-Posting (\u003c= 4.5.0)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["Nelio"],"content_html":"\u003cp\u003eThe Nelio Content - Editorial Calendar \u0026amp; Social Media Auto-Posting plugin for WordPress is affected by an authorization bypass vulnerability (CVE-2026-94505) in all versions up to and including 4.5.0. The vulnerability stems from the plugin's failure to adequately verify user permissions before executing deletion actions on the \u003ccode\u003enc_reusable_social\u003c/code\u003e post type.\u003c/p\u003e\n\u003cp\u003eAn attacker with at least contributor-level access can leverage this flaw to permanently remove social media content authored by other users, including site administrators. This issue represents a significant integrity risk to content calendars and automated social media workflows managed via the plugin. Because the vulnerability exists within the application's authorization logic, it does not require additional software to exploit beyond standard authenticated access to the WordPress backend.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized, permanent deletion of reusable social media messages across the WordPress installation. This impact primarily affects marketing operations and editorial calendars, potentially causing significant disruption to social media campaigns and loss of prepared content. The vulnerability affects all users running Nelio Content versions 4.5.0 or older.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the update of the Nelio Content plugin to the latest version. Monitor WordPress administrative access logs for unusual deletion activity associated with users assigned the 'contributor' role.\u003c/p\u003e\n","date_modified":"2026-10-03T08:54:41Z","date_published":"2026-10-03T08:54:41Z","id":"https://feed.craftedsignal.io/briefs/2026-10-nelio-auth-bypass/","summary":"An authorization bypass vulnerability in the Nelio Content WordPress plugin allows authenticated contributors to delete arbitrary reusable social messages.","title":"Authorization Bypass in Nelio Content WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-nelio-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Nelio","version":"https://jsonfeed.org/version/1.1"}