CyberRota Analysis
AI-GeneratedThe ECS WordPress plugin prior to version 4.3.8 is vulnerable due to a lack of capability and ownership checks on its dynamic repeater actions, allowing users with contributor-level access or higher to manipulate post configurations and site-wide presets. This could lead to unauthorized alterations and deletions of content, potentially compromising site integrity. WordPress site administrators and developers using this plugin should prioritize upgrading to the latest version to mitigate these risks.
Original NVD Description
The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who can open the page builder, allowing users with a contributor-level account or above to read, alter and delete the binding configuration of posts they do not own and to change the ECS WordPress plugin before 4.3.8's site-wide presets.