# Echo Knowledge Base – Documentation, FAQs, AI Chat & AI Search <= 17.214.0 - Authenticated (Author+) Insecure Direct Object Reference to Arbitrary Post Read, Modification and Deletion via FAQ AJAX Actions

- **ID:** WPSEC-2026-0505
- **Plugin:** Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search (`echo-knowledge-base`), https://wordpress.org/plugins/echo-knowledge-base/
- **Affected versions:** from 11.41.0 before 17.311.0
- **Fixed in:** 17.311.0 (Update to 17.311.0 or later.)
- **Severity:** High 7.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/echo-knowledge-base
- **Fix released:** 2026-10-04
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0505/

## Description

The Echo Knowledge Base plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 11.41.0 up to, and including, 17.214.0 via the 'epkb_save_faq', 'epkb_get_faq' and 'epkb_delete_faq' AJAX actions due to missing validation that the supplied 'faq_id' refers to an FAQ post. This makes it possible for authenticated attackers with FAQ access, which is granted to Author-level users and above by default, to permanently delete arbitrary posts and pages, overwrite their title and content (turning them into published FAQs), and read the title and content of arbitrary posts, including private and draft posts belonging to other users.

## References

- https://wpsec.com/vuln/WPSEC-2026-0505/
- https://plugins.svn.wordpress.org/echo-knowledge-base/tags/17.311.0/
- https://wordpress.org/plugins/echo-knowledge-base/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0505/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
