PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19613 ECS CVE debrief

The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom field values from a user-supplied post identifier, allowing users with a contributor-level account or above to read custom field values and post metadata from posts they do not own, including private and draft ones.

Vendor
ECS
Product
ECS WordPress plugin
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-16
Original CVE updated
2026-08-26
Advisory published
2026-08-16
Advisory updated
2026-08-26

Who should care

Administrators and users of the ECS WordPress plugin, as well as security teams monitoring for potential information disclosure vulnerabilities in WordPress plugins, should be aware of this vulnerability and take necessary actions to protect their systems. This includes reviewing user roles and permissions, monitoring for suspicious activity, and applying the vendor-provided patch or upgrading to version 4.3.10 or later. Additionally, defenders should verify affected systems and review compensating controls for exposed systems while remediation is scheduled and verified.

Technical summary

The ECS WordPress plugin before 4.3.10 does not perform necessary checks when reading custom field values from user-supplied post identifiers, allowing users with contributor-level access or higher to access post metadata and custom field values from posts they do not own. This could potentially lead to information disclosure. The vulnerability is caused by a lack of ownership or post-status checks. Administrators should review and adjust user roles and permissions to prevent unauthorized access.

Defensive priority

Medium-priority defensive actions are recommended due to the potential for information disclosure.

Recommended defensive actions

  • Inventory and verify affected systems for the ECS WordPress plugin version.
  • Restrict access to sensitive post metadata and custom fields.
  • Monitor for suspicious activity related to post access and data retrieval.
  • Apply the vendor-provided patch or upgrade to version 4.3.10 or later.
  • Review and adjust user roles and permissions to prevent unauthorized access.

Evidence notes

Evidence from the NVD and WPScan suggests that the ECS WordPress plugin has a vulnerability allowing users with contributor-level access or higher to read custom field values and post metadata from posts they do not own. The vulnerability is caused by a lack of ownership or post-status checks when reading custom field values from user-supplied post identifiers. This could potentially lead to information disclosure. Defenders should verify affected systems, review user roles and permissions, and monitor for suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19613 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19613

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19613 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19613

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.