๐Ÿ” CVE Alert

CVE-2026-18807

UNKNOWN 0.0

ECS < 4.3.8 - Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynamic Repeater Handlers

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who can open the page builder, allowing users with a contributor-level account or above to read, alter and delete the binding configuration of posts they do not own and to change the ECS WordPress plugin before 4.3.8's site-wide presets.

Vendor unknown
Product ecs
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ecs

Be the first to know when new unknown vulnerabilities affecting unknown ecs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / ECS
0 < 4.3.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/bf500bf2-1684-4ca1-a8ad-bcff9cbc127c/

Credits

Seongwon LEE WPScan