๐Ÿ” CVE Alert

CVE-2026-18789

UNKNOWN 0.0

Ezoic < 2.23.1 - Unauthenticated Database Export via Content Export REST Routes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side export of the site's database, including user password hashes and password reset tokens, as well as to persistently change some of its settings.

Vendor unknown
Product ezoic
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ezoic

Be the first to know when new unknown vulnerabilities affecting unknown ezoic are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Ezoic
2.6.35 < 2.23.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/1e2ce237-dc91-4144-875a-339b5ea05f3a/

Credits

Usama Arshad WPScan