๐Ÿ” CVE Alert

CVE-2026-14230

UNKNOWN 0.0

ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJAX handlers (gated only by a capability-agnostic nonce that any edit_posts user obtains from the Elementor editor), so a Contributor can write a data-source binding into any post โ€” including admin-authored pages โ€” whose attacker-controlled values are rendered into a widget's repeater output without sanitization, executing JavaScript in the session of any visitor or administrator who views the page.

Vendor unknown
Product ecs
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ecs

Be the first to know when new unknown vulnerabilities affecting unknown ecs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / ECS
0 < 4.3.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/fded2f21-d104-4dcb-8fd1-29db9866cabc/

Credits

Shivamani Vastrala WPScan