Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 15 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Sat, 15 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJAX handlers (gated only by a capability-agnostic nonce that any edit_posts user obtains from the Elementor editor), so a Contributor can write a data-source binding into any post — including admin-authored pages — whose attacker-controlled values are rendered into a widget's repeater output without sanitization, executing JavaScript in the session of any visitor or administrator who views the page. | |
| Title | ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-15T06:00:14.469Z
Reserved: 2026-06-30T12:41:03.303Z
Link: CVE-2026-14230
No data.
Status : Received
Published: 2026-08-15T06:16:55.960
Modified: 2026-08-15T06:16:55.960
Link: CVE-2026-14230
No data.
OpenCVE Enrichment
Updated: 2026-08-15T07:30:05Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')