{
 "id": "WPSEC-2026-0505",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0505/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0505/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0505/index.md",
 "title": "Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search <= 17.214.0 - Authenticated (Author+) Insecure Direct Object Reference to Arbitrary Post Read, Modification and Deletion via FAQ AJAX Actions",
 "description": "The Echo Knowledge Base plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 11.41.0 up to, and including, 17.214.0 via the 'epkb_save_faq', 'epkb_get_faq' and 'epkb_delete_faq' AJAX actions due to missing validation that the supplied 'faq_id' refers to an FAQ post. This makes it possible for authenticated attackers with FAQ access, which is granted to Author-level users and above by default, to permanently delete arbitrary posts and pages, overwrite their title and content (turning them into published FAQs), and read the title and content of arbitrary posts, including private and draft posts belonging to other users.",
 "plugin": {
  "slug": "echo-knowledge-base",
  "name": "Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search",
  "full_name": "Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search",
  "wordpress_org": "https://wordpress.org/plugins/echo-knowledge-base/",
  "advisories_url": "https://wpsec.com/vuln/plugin/echo-knowledge-base/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/echo-knowledge-base"
 },
 "type": "IDOR",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.6,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": "11.41.0",
    "from_inclusive": true,
    "to": "17.311.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 11.41.0 before 17.311.0"
  ]
 },
 "introduced_in": "11.41.0",
 "fixed_in": "17.311.0",
 "remediation": "Update to 17.311.0 or later.",
 "fix_released": "2026-10-04T17:23:04+00:00",
 "published": "2026-10-07T11:46:41+00:00",
 "updated": "2026-10-07T10:53:24.242100+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0505/",
  "https://plugins.svn.wordpress.org/echo-knowledge-base/tags/17.311.0/",
  "https://wordpress.org/plugins/echo-knowledge-base/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/echo-knowledge-base",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}