Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-18807— ECS < 4.3.8 - Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynamic Repeater Handlers

Quick assessment

Affected
Unknown ECS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 ECS WordPress 插件 4.3.8 版本之前,其动态重复器操作缺乏权限或所有权验证,仅依赖于一个对任何能够打开页面构建器的用户都可用的 nonce(一次性令牌)。这使得贡献者及以上级别的用户可以通过该漏洞读取、修改和删除其不拥有的文章的绑定配置,并更改 ECS WordPress 插件 4.3.8 版本之前的站点级预设配置。

AI Predicted 6.5 Difficulty: Easy EPSS 0.25% · P15

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unknown ECS < 4.3.8 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18807

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ECS < 4.3.8 - Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynamic Repeater Handlers
Source: CVE Program / CVE List V5
Vulnerability Description
The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who can open the page builder, allowing users with a contributor-level account or above to read, alter and delete the binding configuration of posts they do not own and to change the ECS WordPress plugin before 4.3.8's site-wide presets.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown ECS 0 ~ 4.3.8 -

II. Public POCs for CVE-2026-18807

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18807

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-18807 (1)

Same Patch Batch · Unknown · 2026-08-15 · 6 CVEs total

CVE-2026-14230 ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings
CVE-2026-14229 ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload
CVE-2026-16541 Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users an
CVE-2026-16611 Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure
CVE-2026-18216 Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login

IV. Related Vulnerabilities

V. Comments for CVE-2026-18807

No comments yet


Leave a comment