Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search <= 17.214.0 - Authenticated (Author+) Insecure Direct Object Reference to Arbitrary Post Read, Modification and Deletion via FAQ AJAX Actions
- ID
- WPSEC-2026-0505
- Plugin
- Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search (echo-knowledge-base)
- Affected
- from 11.41.0 before 17.311.0
- Remediation
- Update to 17.311.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
- Weakness
- CWE-639
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search on WPSec AttackSurface
- Fix released
- Published
Description
The Echo Knowledge Base plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 11.41.0 up to, and including, 17.214.0 via the 'epkb_save_faq', 'epkb_get_faq' and 'epkb_delete_faq' AJAX actions due to missing validation that the supplied 'faq_id' refers to an FAQ post. This makes it possible for authenticated attackers with FAQ access, which is granted to Author-level users and above by default, to permanently delete arbitrary posts and pages, overwrite their title and content (turning them into published FAQs), and read the title and content of arbitrary posts, including private and draft posts belonging to other users.
References
- https://wpsec.com/vuln/WPSEC-2026-0505/
- https://plugins.svn.wordpress.org/echo-knowledge-base/tags/17.311.0/
- https://wordpress.org/plugins/echo-knowledge-base/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS