Review
ECS
CVE published 2026-08-15
CVE-2026-18807
The ECS WordPress plugin before 4.3.8 has a vulnerability allowing users with contributor-level accounts or above to read, alter, and delete binding configurations of posts they do not own and change site-wide presets due to lacking capability and ownership checks on dynamic repeater actions. This issue arises from the plugin's failure to implement proper security measures, potentially leading to unauthor [truncated]