Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-14230— ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings

Quick assessment

Affected
Unknown ECS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ECS WordPress 插件在 4.3.8 版本之前,其动态重复器(Dynamic Repeater)的 AJAX 处理程序未执行权限或对象所有权检查(仅通过一个能力无关的 nonce 进行保护,任何拥有 edit_posts 权限的用户都可以从 Elementor 编辑器获取该 nonce)。因此,Contributor(贡献者)级别的用户可以向任意文章(包括管理员撰写的页面)写入数据源绑定,其中攻击者控制的值会被未经消毒地渲染到小部件的重复器输出中,从而在访问该页面的任何访客或管理员的会话中执行 JavaS

AI Predicted 7.2 Difficulty: Easy EPSS 0.13% · P3

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unknown ECS < 4.3.8 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-14230

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings
Source: CVE Program / CVE List V5
Vulnerability Description
The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJAX handlers (gated only by a capability-agnostic nonce that any edit_posts user obtains from the Elementor editor), so a Contributor can write a data-source binding into any post — including admin-authored pages — whose attacker-controlled values are rendered into a widget's repeater output without sanitization, executing JavaScript in the session of any visitor or administrator who views the page.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown ECS 0 ~ 4.3.8 -

II. Public POCs for CVE-2026-14230

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14230

登录查看更多情报信息。

Vendor Advisories for CVE-2026-14230 (1)

Same Patch Batch · Unknown · 2026-08-15 · 6 CVEs total

CVE-2026-14229 ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload
CVE-2026-16541 Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users an
CVE-2026-16611 Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure
CVE-2026-18807 ECS < 4.3.8 - Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynam
CVE-2026-18216 Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login

IV. Related Vulnerabilities

V. Comments for CVE-2026-14230

No comments yet


Leave a comment