WordPress · Ecs · CVE-2026-18807
**Name of the Vulnerable Software and Affected Versions**
ECS WordPress plugin versions prior to 4.3.8
**Description**
Insufficient capability and ownership checks in dynamic repeater actions allow users with contributor-level accounts or higher to read, modify, and delete the binding configuration of posts they do not own. Additionally, these users can change site-wide presets. The system relies solely on a nonce, which is accessible to any user capable of opening the page builder.
**Recommendations**
Update ECS WordPress plugin to version 4.3.8 or later.