Skip to content

Autoshare for Twitter plugin <= 2.3.1 is vulnerable to Broken Access Control

Moderate
jeffpaul published GHSA-9j39-fp7c-5453 Jan 29, 2026

Package

composer 10up/autoshare-for-twitter (Composer)

Affected versions

<= 2.3.1

Patched versions

>= 2.3.2

Description

Description

The plugin vulnerable to Broken Access Control in `TenUp\AutoshareForTwitter\Core\Post_Transition\tenup_autoshare_retweet() action.

Authenticated users with any role on the WordPress site could trigger a retweet by manipulating an AJAX request.

It is recommended to update to version 2.3.2 to resolve this issue.

Patches

The issue was fixed in Autopost for X (formerly Autoshare for Twitter) 2.3.2.

References

Thank you @nblirwn for responsibly disclosing this issue.

Reporting security vulnerabilities

Please report security bugs found in the source code of the Autoshare for Twitter plugin through the Patchstack Vulnerability Disclosure  Program. The Patchstack team will assist you with verification, CVE assignment, and notify the developers of this plugin.

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs

Credits