CVE-2026-18789: Ezoic < 2.23.1 - Unauthenticated Database Export via Content Export REST Routes
The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side export of the site's database, including user password hashes and password reset tokens, as well as to persistently change some of its settings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ezoic WordPress pluginto a version that resolves this vulnerability.Fixed in 2.23.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18789?
CVE-2026-18789 has a risk score of 85, indicating it is a high-severity vulnerability.
How do I fix CVE-2026-18789?
To fix CVE-2026-18789, update the Ezoic WordPress plugin to version 2.23.1 or later.
What types of data are at risk with CVE-2026-18789?
CVE-2026-18789 allows attackers to access sensitive data including user password hashes and password reset tokens.
Who is affected by CVE-2026-18789?
CVE-2026-18789 affects all versions of the Ezoic WordPress plugin prior to 2.23.1.
What is the nature of the vulnerability in CVE-2026-18789?
CVE-2026-18789 is an unauthenticated database export vulnerability that allows attackers to trigger database exports without authentication.