What is CVE-2026-14230?
CVE-2026-14230 is a critical vulnerability in the ECS WordPress plugin before version 4.3.8. Due to missing capability and object-ownership checks on its AJAX handlers, a user with a "Contributor" role can inject data-source bindings into any post. Immediate update to the latest patched version is required.
Azərbaycanca: CVE-2026-14230 ECS WordPress plaginində aşkar edilmiş kritik boşluqdur. 4.3.8-dən əvvəlki versiyalarda, "Contributor" roluna malik istifadəçi AJAX handler-lərdəki yoxlama çatışmazlığı səbəbindən icazəsiz olaraq istənilən səhifədə data-source binding əməliyyatı apara bilir. Bu, imtiyazların yüksəldilməsinə gətirib çıxarır, təcili olaraq ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the ECS plugin are affected by CVE-2026-14230?
This vulnerability affects versions of the ECS WordPress plugin prior to 4.3.8.
What can a user with a Contributor role do by exploiting this vulnerability?
Due to missing capability checks on its AJAX handlers, a user with a Contributor role can inject data-source bindings into any post without authorization.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.