CyberRota Analysis
AI-GeneratedThe ECS WordPress plugin prior to version 4.3.8 is vulnerable as it fails to validate post status or user capabilities when processing AJAX requests for Elementor documents. This oversight allows unauthenticated users to access and retrieve the rendered content of unpublished documents, potentially exposing sensitive information. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of its AJAX actions, allowing unauthenticated users to retrieve the rendered content of unpublished (private, draft, pending) documents by supplying their identifier.