PT-2026-72162 · WordPress · Ecs

·

CVE-2026-14230

·

Published

2026-08-15

·

Updated

2026-08-17

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ECS WordPress plugin versions prior to 4.3.8
Description Insufficient capability and object-ownership checks in Dynamic Repeater AJAX handlers allow a user with Contributor privileges to inject data-source bindings into any post, including those authored by administrators. Because the values are rendered into a widget's repeater output without proper sanitization, this can lead to the execution of arbitrary JavaScript in the session of any visitor or administrator viewing the affected page. The handlers are protected only by a capability-agnostic nonce that any user with edit posts permissions can obtain via the Elementor editor.
Recommendations Update ECS WordPress plugin to version 4.3.8 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14230

Affected Products

Ecs