# Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search <= 17.214.0 - Unauthenticated REST API Nonce Exposure via AI Chat 'start-session' Endpoint

- **ID:** WPSEC-2026-0503
- **Plugin:** Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search (`echo-knowledge-base`), https://wordpress.org/plugins/echo-knowledge-base/
- **Affected versions:** from 16.011.0 before 17.311.0
- **Fixed in:** 17.311.0 (Update to 17.311.0 or later.)
- **Severity:** High 7.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
- **Weakness:** CWE-346
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/echo-knowledge-base
- **Fix released:** 2026-10-04
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0503/

## Description

The Echo Knowledge Base plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 16.011.0 up to, and including, 17.214.0 via the AI Chat 'start-session' REST endpoint. The endpoint authenticates the caller from the WordPress login cookie without requiring a REST nonce or validating the request origin, and returns a newly generated REST API nonce for that user. Because the WordPress REST API allows credentialed cross-origin requests, a page on another origin can read this response. This makes it possible for unauthenticated attackers to obtain the REST API nonce of a logged-in user who visits an attacker-controlled page, and to use it to perform authenticated REST API requests as that user; against an administrator this can lead to full site compromise. Exploitation requires the AI Chat feature to be enabled and the victim's browser to send the WordPress login cookies with the cross-origin request, for example from a page on a subdomain of the same site.

## References

- https://wpsec.com/vuln/WPSEC-2026-0503/
- https://plugins.svn.wordpress.org/echo-knowledge-base/tags/17.311.0/
- https://wordpress.org/plugins/echo-knowledge-base/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0503/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
