AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14229

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The ECS WordPress plugin prior to version 4.3.8 is vulnerable as it fails to validate post status or user capabilities when processing AJAX requests for Elementor documents. This oversight allows unauthenticated users to access and retrieve the rendered content of unpublished documents, potentially exposing sensitive information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-14229
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
WordPress

Original NVD Description

The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of its AJAX actions, allowing unauthenticated users to retrieve the rendered content of unpublished (private, draft, pending) documents by supplying their identifier.