high · CVSS v3 7.6
CVE-2026-97277
CVE-2026-97277 exposes a broken access control flaw in the Social Boost WordPress plugin, allowing unauthorized users to perform privileged
Overview
CVE-2026-97277 exposes a broken access control flaw in the Social Boost WordPress plugin, allowing unauthorized users to perform privileged actions. The vulnerability exists in all versions up to 3.6.2 and can be exploited by anyone with access to the site. It is rated high severity with a CVSS v3 score of 7.6.
Description
Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.
Impact
The flaw permits attackers to bypass subscriber restrictions, potentially exposing sensitive content and modifying site settings. This compromises confidentiality and integrity of the website’s data and can lead to unauthorized content publication. Site administrators and subscribers are directly impacted.
Remediation
Upgrade Social Boost to version 3.6.3 or later. Verify that subscriber roles have only the intended capabilities and audit role permissions. If the plugin is not required, disable or uninstall it. Monitor site logs for suspicious activity.
Risk context
The vulnerability is classified as high severity with a CVSS v3 score of 7.6, indicating a significant risk to affected sites. Defenders should prioritize patching to mitigate potential exploitation.
Affected products
- Social Boost
Scores
- Severity
- high
- CVSS v2
- 8
- CVSS v3
- 7.6
- CVSS v4
- —
- EPSS
- —