CVE 4.3 MEDIUM

Blog2Social: Social Media Auto Post & Scheduler <= 8.6.0 - Incorrect Authorization to Video File Upload_CVE-2025-12563

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Description

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an incorrect capability check on theuploadVideo() function in all versions up to, and including, 8.6.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload mp4 files to the 'wp-content/uploads/<YYYY>/<MM>/' directory.

Basic Information

ID CVE-2025-12563
Source Wordfence
Published Nov 6, 2025 at 04:36

Affected Product

Vendor pr-gateway
Product Blog2Social: Social Media Auto Post & Scheduler
Version *
Affected Versions pr-gateway Blog2Social: Social Media Auto Post & Scheduler *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.