Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 18 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 17 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Essentialplugin
Essentialplugin essential Chat Support Wordpress Wordpress wordpress |
|
| Vendors & Products |
Essentialplugin
Essentialplugin essential Chat Support Wordpress Wordpress wordpress |
Sat, 16 May 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to reset all plugin configuration settings — including general settings, display rules, custom CSS, and WooCommerce tab settings — to their defaults by sending a POST request with ecs_reset_settings=1. | |
| Title | Essential Chat Support <= 1.0.1 - Missing Authorization to Unauthenticated Settings Reset via 'ecs_reset_settings' Parameter | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-18T17:40:28.240Z
Reserved: 2026-05-15T13:35:04.229Z
Link: CVE-2026-8681
Updated: 2026-05-18T17:40:14.873Z
Status : Deferred
Published: 2026-05-16T03:16:21.007
Modified: 2026-06-17T11:04:16.790
Link: CVE-2026-8681
No data.
OpenCVE Enrichment
Updated: 2026-05-17T17:01:04Z