{
 "id": "WPSEC-2026-0503",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0503/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0503/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0503/index.md",
 "title": "Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search <= 17.214.0 - Unauthenticated REST API Nonce Exposure via AI Chat 'start-session' Endpoint",
 "description": "The Echo Knowledge Base plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 16.011.0 up to, and including, 17.214.0 via the AI Chat 'start-session' REST endpoint. The endpoint authenticates the caller from the WordPress login cookie without requiring a REST nonce or validating the request origin, and returns a newly generated REST API nonce for that user. Because the WordPress REST API allows credentialed cross-origin requests, a page on another origin can read this response. This makes it possible for unauthenticated attackers to obtain the REST API nonce of a logged-in user who visits an attacker-controlled page, and to use it to perform authenticated REST API requests as that user; against an administrator this can lead to full site compromise. Exploitation requires the AI Chat feature to be enabled and the victim's browser to send the WordPress login cookies with the cross-origin request, for example from a page on a subdomain of the same site.",
 "plugin": {
  "slug": "echo-knowledge-base",
  "name": "Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search",
  "full_name": "Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search",
  "wordpress_org": "https://wordpress.org/plugins/echo-knowledge-base/",
  "advisories_url": "https://wpsec.com/vuln/plugin/echo-knowledge-base/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/echo-knowledge-base"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-346"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.5,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": "16.011.0",
    "from_inclusive": true,
    "to": "17.311.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 16.011.0 before 17.311.0"
  ]
 },
 "introduced_in": "16.011.0",
 "fixed_in": "17.311.0",
 "remediation": "Update to 17.311.0 or later.",
 "fix_released": "2026-10-04T17:23:04+00:00",
 "published": "2026-10-07T11:46:41+00:00",
 "updated": "2026-10-07T10:53:24.242100+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0503/",
  "https://plugins.svn.wordpress.org/echo-knowledge-base/tags/17.311.0/",
  "https://wordpress.org/plugins/echo-knowledge-base/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/echo-knowledge-base",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}