Impact
The vulnerability in the ECS WordPress plugin allows an attacker with a contributor-level account or higher to read custom field values and post metadata from posts that the user does not own, including private or draft posts. Because the plugin does not enforce ownership or post-status checks when dynamic repeater data sources fetch custom fields from a user-supplied post identifier, the attacker can access sensitive information that should be restricted to the post owner or administrators. This flaw results in the leakage of potentially confidential post content and metadata to unauthorized users.
Affected Systems
All installations of the ECS plugin version earlier than 4.3.10 are affected. The vulnerability applies to the plugin itself regardless of the WordPress site configuration, so any site running a susceptible version of ECS is at risk. No specific sub‑versions are listed beyond the pre‑4.3.10 threshold, so the recommendation applies broadly to all older releases.
Risk and Exploitability
The exploit requires the attacker to be a logged‑in contributor or higher, which is a relatively low‑bar prerequisite on most sites with WordPress roles. While an EPSS score is unavailable, the lack of a KEV listing indicates no known public exploitation. The attack vector is internal to the site and relies on legitimate user credentials; however, once the contributor privilege is obtained, arbitrary read of post data is possible. The overall risk is moderate, driven by the potential for sensitive post disclosure but constrained by the need for authenticated access.
OpenCVE Enrichment