ECS WordPress 插件在 4.3.8 版本之前,其动态重复器(Dynamic Repeater)的 AJAX 处理程序未执行权限或对象所有权检查(仅通过一个能力无关的 nonce 进行保护,任何拥有 edit_posts 权限的用户都可以从 Elementor 编辑器获取该 nonce)。因此,Contributor(贡献者)级别的用户可以向任意文章(包括管理员撰写的页面)写入数据源绑定,其中攻击者控制的值会被未经消毒地渲染到小部件的重复器输出中,从而在访问该页面的任何访客或管理员的会话中执行 JavaS
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14229 | ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload | |
| CVE-2026-16541 | Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users an | |
| CVE-2026-16611 | Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure | |
| CVE-2026-18807 | ECS < 4.3.8 - Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynam | |
| CVE-2026-18216 | Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login |
No comments yet