cleantalk
Vulnerabilities and Security Researches

Elementor Custom Skin, CVE-2026-18807

CVE, Research URL

CVE-2026-18807

Application

Elementor Custom Skin

Published on
Aug 15, 2026
Research Description
The ECS WordPress plugin before 4.3.8 does not have capability or ownership checks on its dynamic repeater actions, relying only on a nonce available to any user who can open the page builder, allowing users with a contributor-level account or above to read, alter and delete the binding configuration of posts they do not own and to change the ECS WordPress plugin before 4.3.8's site-wide presets.
Affected versions
max 4.3.8.
Status
vulnerable