PatchSiren cyber security CVE debrief
CVE-2026-19613 ECS CVE debrief
The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom field values from a user-supplied post identifier, allowing users with a contributor-level account or above to read custom field values and post metadata from posts they do not own, including private and draft ones.
- Vendor
- ECS
- Product
- ECS WordPress plugin
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-16
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-16
- Advisory updated
- 2026-08-26
Who should care
Administrators and users of the ECS WordPress plugin, as well as security teams monitoring for potential information disclosure vulnerabilities in WordPress plugins, should be aware of this vulnerability and take necessary actions to protect their systems. This includes reviewing user roles and permissions, monitoring for suspicious activity, and applying the vendor-provided patch or upgrading to version 4.3.10 or later. Additionally, defenders should verify affected systems and review compensating controls for exposed systems while remediation is scheduled and verified.
Technical summary
The ECS WordPress plugin before 4.3.10 does not perform necessary checks when reading custom field values from user-supplied post identifiers, allowing users with contributor-level access or higher to access post metadata and custom field values from posts they do not own. This could potentially lead to information disclosure. The vulnerability is caused by a lack of ownership or post-status checks. Administrators should review and adjust user roles and permissions to prevent unauthorized access.
Defensive priority
Medium-priority defensive actions are recommended due to the potential for information disclosure.
Recommended defensive actions
- Inventory and verify affected systems for the ECS WordPress plugin version.
- Restrict access to sensitive post metadata and custom fields.
- Monitor for suspicious activity related to post access and data retrieval.
- Apply the vendor-provided patch or upgrade to version 4.3.10 or later.
- Review and adjust user roles and permissions to prevent unauthorized access.
Evidence notes
Evidence from the NVD and WPScan suggests that the ECS WordPress plugin has a vulnerability allowing users with contributor-level access or higher to read custom field values and post metadata from posts they do not own. The vulnerability is caused by a lack of ownership or post-status checks when reading custom field values from user-supplied post identifiers. This could potentially lead to information disclosure. Defenders should verify affected systems, review user roles and permissions, and monitor for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19613 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19613
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19613 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19613
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/0d4ccc34-632a-4058-9220-b3cce7a942dd/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.