Cross-Site Scripting Vulnerability in ECS Plugin for WordPress
CVE-2026-14230
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-14230?
The ECS WordPress plugin prior to version 4.3.8 lacks adequate capability and object-ownership checks for its Dynamic Repeater AJAX handlers. This flaw allows a Contributor level user to inject their own data-source bindings into any post, including those authored by admins. The injected values can be unsafe and are rendered without sanitization in a widget's output. As a result, this opens up the possibility for executing malicious JavaScript within the browser sessions of visitors or administrators viewing the compromised page.
Affected Version(s)
ECS 0 < 4.3.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.