AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18807

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The ECS WordPress plugin prior to version 4.3.8 is vulnerable due to a lack of capability and ownership checks on its dynamic repeater actions, allowing users with contributor-level access or higher to manipulate post configurations and site-wide presets. This could lead to unauthorized alterations and deletions of content, potentially compromising site integrity. WordPress site administrators and developers using this plugin should prioritize upgrading to the latest version to mitigate these risks.

CVE
CVE-2026-18807
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
WordPress

Original NVD Description

The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who can open the page builder, allowing users with a contributor-level account or above to read, alter and delete the binding configuration of posts they do not own and to change the ECS WordPress plugin before 4.3.8's site-wide presets.