ECS – Ele Custom Skin for Elementor

ECS – Ele Custom Skin for Elementor has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2026; all 2 are fixed as of August 2026. Their average CVSS score is 5.8, and the most serious one scores 6.4 out of 10. 2026 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for ECS – Ele Custom Skin for Elementor has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. ECS – Ele Custom Skin for Elementor is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.8/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all ECS – Ele Custom Skin for Elementor vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2026-14230

ECS <= 4.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
ECS – Ele Custom Skin for Elementor banner
Latestv4.3.11

ECS – Ele Custom Skin for Elementor

dudaster

Author

dudaster

4.6(117)
92/100
Last Updated
2026-08-20 (1d ago)
Active Installs
100,000+
Downloads
2,047,797
Requires WP
6.0+
Requires PHP
8.0+
Tested up to
WP 7.1
Created
2018-04-18 (9y ago)

ECS adds what Elementor doesn’t have — without replacing what it does well. Every feature is a standalone module. Enable only what you need from ECS → Modules in the WordPress admin. Unused modules load zero CSS, zero JS, and register no hooks. 🎨 Dark Mode Colours A Default Colours tab appears inside Elementor’s Site Settings, right next to Global Colors. Set a Default and a Dark Mode colour for every global colour slot. Dark mode colours are written as CSS variables — no JavaScript swapping, pure CSS, zero flash. A fallback swatch shows the default colour when the dark slot is empty. The Dark Mode Switcher widget lets visitors toggle between light and dark with full style controls. 📐 Container Layout Two additional layout modes for Elementor Flex Containers: Slider Mode — Turn any container into a CSS-only slider. No JS library, no dependencies. Custom Layout — Pick a Theme Builder template as the layout frame. Place ECS Placeholder widgets inside the template; ECS distributes the container’s children into those slots automatically. Supports cycling and graceful fallback. Works live in the Elementor editor. 🔁 Loop Custom Layout Arrange Loop Grid items inside a Custom Layout template using ECS Placeholder widgets — powered by Elementor’s native Loop Grid query. Full editorial control over the item grid without leaving Elementor. 📱 Menu Responsive Turn any Elementor Nav Menu widget into a responsive hamburger menu. Layout, alignment, animation, and breakpoint controls — all from the Elementor panel. ✍️ Editorial Text Wrap images inside text blocks with float controls and captions. Magazine-style editorial layouts built entirely in Elementor. 🎨 Style Templates Save any widget’s Style tab settings as a named preset and apply them to other widgets of the same type in one click — across pages, templates, and sites. Export and import your full style library as JSON. 🛠 JSON PowerEdit Edit any Elementor widget’s raw settings JSON directly from the panel. Raw textarea for paste-and-replace, interactive tree view for surgical edits. Keyboard shortcut: Ctrl/Cmd + Enter to apply. ✅ Legacy (ECS 3.x — backward compatibility) The original loop skin functionality is preserved in the Legacy module for existing sites built with ECS 3.x. If you’re updating from ECS 3.x, this module activates automatically. For new projects, use Elementor’s native Loop Builder. Note: This plugin requires Elementor (free). Container Layout (Custom Layout mode) and Style Templates require Elementor Pro.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C