PatchSiren

ECS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ECS CVE published 2026-08-16

CVE-2026-19613

The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom field values from a user-supplied post identifier, allowing users with a contributor-level account or above to read custom field values and post metadata from posts they do not own, including private and draft ones.

MEDIUM ECS CVE published 2026-08-15

CVE-2026-18807

The ECS WordPress plugin before 4.3.8 has a vulnerability allowing users with contributor-level accounts or above to read, alter, and delete binding configurations of posts they do not own and change site-wide presets due to lacking capability and ownership checks on dynamic repeater actions. This issue arises from the plugin's failure to implement proper security measures, potentially leading to unauthor [truncated]

MEDIUM ECS CVE published 2026-08-15

CVE-2026-14229

The ECS WordPress plugin before 4.3.8 allows unauthenticated users to retrieve rendered content of unpublished documents through AJAX actions due to insufficient checks on post status and user capabilities. This vulnerability impacts WordPress site administrators, security teams, and users of the ECS WordPress plugin, potentially affecting the confidentiality of unpublished content and the integrity of Wo [truncated]