CVE-2026-18807
Deferred Deferred - Pending Action

ECS Plugin Dynamic Repeater Actions Privilege Escalation

Vulnerability report for CVE-2026-18807, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-26

Assigner: WPScan

Description

The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who can open the page builder, allowing users with a contributor-level account or above to read, alter and delete the binding configuration of posts they do not own and to change the ECS WordPress plugin before 4.3.8's site-wide presets.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-26
Generated
2026-09-04
AI Q&A
2026-08-15
EPSS Evaluated
2026-09-03
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ecs wordpress_plugin to 4.3.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the ECS WordPress plugin versions before 4.3.8. It allows users with contributor-level access or higher to exploit dynamic repeater handlers due to missing capability or ownership checks. These users can read, modify, or delete the binding configuration of posts they do not own and change the plugin's global presets by relying on a nonce available to any user with page builder access.

Detection Guidance

Check the installed version of the ECS WordPress plugin. If it is below 4.3.8, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files for version details.

Impact Analysis

If you use the ECS WordPress plugin before version 4.3.8, an attacker with contributor-level access or higher could alter or delete your post configurations, modify global plugin settings, or access sensitive data. This could disrupt your website's functionality or expose confidential information.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, potentially violating GDPR or HIPAA compliance. Unauthorized changes to post configurations or plugin settings might expose personal or protected health information, resulting in legal and regulatory penalties.

Mitigation Strategies

Update the ECS WordPress plugin to version 4.3.8 or later immediately. Remove unnecessary user accounts with contributor-level access or higher. Review and restrict permissions for existing users.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18807. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart