The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom field values from a user-supplied post identifier, allowing users with a contributor-level account or above to read custom field values and post metadata from posts they do not own, including private and draft ones.
The ECS WordPress plugin before 4.3.8 has a vulnerability allowing users with contributor-level accounts or above to read, alter, and delete binding configurations of posts they do not own and change site-wide presets due to lacking capability and ownership checks on dynamic repeater actions. This issue arises from the plugin's failure to implement proper security measures, potentially leading to unauthor [truncated]
The ECS WordPress plugin before 4.3.8 allows unauthenticated users to retrieve rendered content of unpublished documents through AJAX actions due to insufficient checks on post status and user capabilities. This vulnerability impacts WordPress site administrators, security teams, and users of the ECS WordPress plugin, potentially affecting the confidentiality of unpublished content and the integrity of Wo [truncated]