
CVE-2026-14230 The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJAX handlers (gated only by a capability-agnost… https://www.cve.org/CVERecord?id=CVE-2026-14230
Post summary
The content announces CVE‑2026‑14230 affecting the ECS WordPress plugin, noting missing capability checks on AJAX handlers, but provides no PoC, exploit, patch, or active exploitation details.
