CVE-2026-18807

NONE
Updated Aug 15, 2026
WordPress
Parameter Value
Affected Versions before 4.3.8
Vendor WordPress
Public PoC No

The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who can open the page builder, allowing users with a contributor-level account or above to read, alter and delete the binding configuration of posts they do not own and to change the ECS WordPress plugin before 4.3.8's site-wide presets.