WordPress Plugin Vulnerabilities

ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF Source

Description

The plugin does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom field values from a user-supplied post identifier, allowing users with a contributor-level account or above to read custom field values and post metadata from posts they do not own, including private and draft ones.

Proof of Concept

Affects Plugins

Fixed in 4.3.10

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
Erwan LR (WPScan)
Submitter
Erwan LR (WPScan)
Verified
Yes

Timeline

Publicly Published
2026-08-14 (about 2 days ago)
Added
2026-08-14 (about 1 day ago)
Last Updated
2026-08-14 (about 1 day ago)

Other