What is CVE-2026-14229?
The ECS WordPress plugin before version 4.3.8 fails to check post status or user capabilities when rendering Elementor documents via AJAX actions. This allows unauthenticated users to retrieve the rendered content of unpublished (private, draft, pending) documents. Immediate update to version 4.3.8 or later is recommended.
Azərbaycanca: ECS WordPress plugin-in 4.3.8 versiyasından əvvəlki versiyalarında Elementor sənədlərini yükləyərkən post statusunu və ya icazələri yoxlamır. Bu zəiflik autentifikasiya olunmamış istifadəçilərə AJAX sorğuları vasitəsilə dərc olunmamış (şəxsi, qaralama, gözləmədə olan) sənədlərin məzmununu əldə etməyə imkan verir. Plugin-i dərhal 4.3.8 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ1
What security flaw exists in older versions of the ECS WordPress plugin?
The ECS WordPress plugin before version 4.3.8 fails to check post status or user capabilities when rendering Elementor documents via AJAX actions. This allows unauthenticated users to retrieve the rendered content of unpublished (private, draft, pending) documents.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.