Impact
The ECS WordPress plugin before version 4.3.8 fails to verify post status or user capabilities when processing the ecsload AJAX request. An attacker can supply a document identifier to this endpoint and retrieve the rendered HTML of any unpublished (private, draft, or pending) Elementor document, resulting in accidental disclosure of confidential content.
Affected Systems
All installations of the ECS plugin running versions older than 4.3.8 are affected. The vulnerability is specific to the ecsload AJAX action and does not require physical access; it can be exploited through any web browser.
Risk and Exploitability
Because the vulnerability is unauthenticated and requires only a simple HTTP request, an attacker can abuse it from any location with network access to the site. The EPSS score is not listed, but the lack of an authentication check indicates a high likelihood of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog, but administrators should treat it as a high‑severity confidentiality issue until a patch is applied.
OpenCVE Enrichment