The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side export of the site's database, including user password hashes and password reset tokens, as well as to persistently change some of its settings.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-12 06:20
Updated : 2026-08-26 16:30
NVD link : CVE-2026-18789
Mitre link : CVE-2026-18789
CVE.ORG link : CVE-2026-18789
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
