CVE-2026-8681Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to reset all plugin configuration settings — including general settings, display rules, custom CSS, and WooCommerce tab settings — to their defaults by sending a POST request with ecs_reset_settings=1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-16); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-05-16: 2Mentions · 2026-05-17: 2Patch / Workaround · 2026-05-16: 1Technical Details · 2026-05-16: 2Technical Details · 2026-05-17: 205-1605-17
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-162
Disclosure1Patch1
2026-05-172
Disclosure2
Full discourse4 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🚨 CVE-2026-8681: The Essential Chat Support plugin for WordPress is vulnerable to an authorization bypass in versions up to 1.0.1. Unauthenticated attackers may be able to reset plugin settings and potentially take control of support workflows. Patch fast. #WordPress #CVE #CyberSecurity

    Post summary

    The Essential Chat Support plugin for WordPress has an authorization‑bypass flaw (CVE‑2026‑8681) and the release notes urge users to patch quickly; no exploit or active attacks are reported.

    1001090
    1.3K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-8681 The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properl… https://www.cve.org/CVERecord?id=CVE-2026-8681 ----- Traducción: CVE-2026-8681 El … http://infoflow.cloud`

    Post summary

    The post announces that the Essential Chat Support WordPress plugin contains an authorization bypass flaw (CVE-2026-8681) and directs readers to the CVE record for more details.

    0000056
    78 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8681 The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properl… https://www.cve.org/CVERecord?id=CVE-2026-8681

    Post summary

    CVE-2026-8681 exposes an authorization bypass in the Essential Chat Support WordPress plugin for all versions up to and including 1.0.1.

    00000512
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8681 Authorization Bypass in Essential Chat Support Plugin for WordPress Up to 1.0.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8681

    Post summary

    The post announces the discovery of CVE-2026-8681, detailing an authorization bypass in the Essential Chat Support WordPress plugin up to version 1.0.1, without indicating PoC, exploit, active use, patch, or false-positive claims.

    0000096
    4.0K followersView on X

Explore more