What is CVE-2026-18807?
CVE-2026-18807 is a vulnerability in the ECS WordPress plugin before version 4.3.8, where missing capability checks on dynamic repeater actions allow users with contributor-level access or above to read, alter, and delete binding configurations. The flaw relies only on a nonce available to any user who can use the page builder. Immediate update to version 4.3.8 or later is recommended.
Azərbaycanca: CVE-2026-18807, ECS WordPress plagininin 4.3.8-dən əvvəlki versiyalarında aşkar edilmiş zəiflikdir. Plaginin dynamic repeater əməliyyatlarında səlahiyyət (capability) yoxlaması olmadığı üçün contributor səviyyəli istifadəçilər belə binding konfiqurasiyalarını oxuya, dəyişdirə və silə bilər. Plagini dərhal 4.3.8 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What level of users can exploit CVE-2026-18807?
Users with contributor-level access or above can exploit this vulnerability.
How to protect the ECS WordPress plugin from CVE-2026-18807?
It is recommended to immediately update the plugin to version 4.3.8 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.