
CVE-2026-14229 The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of its AJAX actions… https://www.cve.org/CVERecord?id=CVE-2026-14229
Post summary
The post announces CVE‑2026‑14229, a flaw in the ECS WordPress plugin (pre‑4.3.8) that neglects to verify post status or user capabilities when rendering Elementor documents through AJAX actions.
