Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search <= 17.214.0 - Unauthenticated REST API Nonce Exposure via AI Chat 'start-session' Endpoint

High 7.5 CWE-346Fixed in 17.311.0
ID
WPSEC-2026-0503
Plugin
Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search (echo-knowledge-base)
Affected
from 16.011.0 before 17.311.0
Remediation
Update to 17.311.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness
CWE-346
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search on WPSec AttackSurface
Fix released
Published

Description

The Echo Knowledge Base plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 16.011.0 up to, and including, 17.214.0 via the AI Chat 'start-session' REST endpoint. The endpoint authenticates the caller from the WordPress login cookie without requiring a REST nonce or validating the request origin, and returns a newly generated REST API nonce for that user. Because the WordPress REST API allows credentialed cross-origin requests, a page on another origin can read this response. This makes it possible for unauthenticated attackers to obtain the REST API nonce of a logged-in user who visits an attacker-controlled page, and to use it to perform authenticated REST API requests as that user; against an administrator this can lead to full site compromise. Exploitation requires the AI Chat feature to be enabled and the victim's browser to send the WordPress login cookies with the cross-origin request, for example from a page on a subdomain of the same site.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0