Impact
The ECS WordPress plugin before version 4.3.8 fails to verify post status or user capabilities when processing the ecsload AJAX request. An attacker can supply a document identifier to this endpoint and retrieve the rendered HTML of any unpublished (private, draft, or pending) Elementor document, resulting in accidental disclosure of confidential content.
Affected Systems
All installations of the ECS plugin running versions older than 4.3.8 are affected. The vulnerability is specific to the ecsload AJAX action and does not require physical access; it can be exploited through any web browser.
Risk and Exploitability
Because the vulnerability is unauthenticated and requires only a simple HTTP request, an attacker can abuse it from any location with network access to the site. The EPSS score is < 1%, indicating a very low but nonzero likelihood of exploitation, yet the lack of an authentication check indicates that it could still be abused. The vulnerability is not currently listed in the CISA KEV catalog, but administrators should treat it as a high‑severity confidentiality issue until a patch is applied.
OpenCVE Enrichment