Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search <= 17.214.0 - Authenticated (Author+) Insecure Direct Object Reference to Arbitrary Post Read, Modification and Deletion via FAQ AJAX Actions

High 7.6 CWE-639Fixed in 17.311.0
ID
WPSEC-2026-0505
Plugin
Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search (echo-knowledge-base)
Affected
from 11.41.0 before 17.311.0
Remediation
Update to 17.311.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Weakness
CWE-639
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search on WPSec AttackSurface
Fix released
Published

Description

The Echo Knowledge Base plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 11.41.0 up to, and including, 17.214.0 via the 'epkb_save_faq', 'epkb_get_faq' and 'epkb_delete_faq' AJAX actions due to missing validation that the supplied 'faq_id' refers to an FAQ post. This makes it possible for authenticated attackers with FAQ access, which is granted to Author-level users and above by default, to permanently delete arbitrary posts and pages, overwrite their title and content (turning them into published FAQs), and read the title and content of arbitrary posts, including private and draft posts belonging to other users.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0