
CVE-2026-18807 The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who… https://www.cve.org/CVERecord?id=CVE-2026-18807
Post summary
The excerpt references CVE-2026-18807, noting a lack of capability checks in the ECS WordPress plugin’s dynamic repeater actions, but provides no PoC, exploit, patch, or active exploitation information.
