WordPress Plugin Vulnerabilities

ECS < 4.3.8 - Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynamic Repeater Handlers

Description

The plugin does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who can open the page builder, allowing users with a contributor-level account or above to read, alter and delete the binding configuration of posts they do not own and to change the plugin's site-wide presets.

Proof of Concept

Affects Plugins

Fixed in 4.3.8

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Seongwon LEE
Submitter
Seongwon LEE
Verified
Yes

Timeline

Publicly Published
2026-08-13 (about 2 days ago)
Added
2026-08-13 (about 1 day ago)
Last Updated
2026-08-13 (about 1 day ago)

Other