PT-2026-72161 · WordPress · Ecs
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ECS WordPress plugin versions prior to 4.3.8
Description
An issue exists where the plugin fails to verify post status or user capabilities when rendering an Elementor document via AJAX actions. This allows unauthenticated users to retrieve the rendered content of unpublished documents, such as those marked as private, draft, or pending, by providing the document identifier.
Recommendations
Update the ECS WordPress plugin to version 4.3.8 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecs