AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18789

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Ezoic WordPress plugin prior to version 2.23.1 is vulnerable due to inadequate access controls on its content export functionality, enabling unauthenticated attackers to export the site's database, which may include sensitive user information such as password hashes and reset tokens. This vulnerability poses a significant risk of data exposure and unauthorized configuration changes. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-18789
Severity
HIGH
CVSS
7.5
EPSS
0.26%
WordPress

Original NVD Description

The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side export of the site's database, including user password hashes and password reset tokens, as well as to persistently change some of its settings.