CVE-2026-14229: ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload
The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of its AJAX actions, allowing unauthenticated users to retrieve the rendered content of unpublished (private, draft, pending) documents by supplying their identifier.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14229?
CVE-2026-14229 has a risk rating of 64, indicating a significant vulnerability that requires attention.
How do I fix CVE-2026-14229?
To fix CVE-2026-14229, update the ECS WordPress plugin to version 4.3.8 or later.
What does CVE-2026-14229 allow unauthenticated users to do?
CVE-2026-14229 allows unauthenticated users to access and retrieve unpublished documents through an AJAX request.
Which version of ECS is affected by CVE-2026-14229?
CVE-2026-14229 affects all versions of the ECS WordPress plugin prior to 4.3.8.
What type of content is exposed by CVE-2026-14229?
CVE-2026-14229 exposes private, draft, and pending documents to unauthorized users.