CVE-2026-32481: WordPress Ezoic plugin <= 2.22.11 - Broken Authentication vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
Affected Software
1 affected component
WordPress Ezoic plugin<=2.22.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ezoic pluginto a version that resolves this vulnerability.Fixed in 2.23.1
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed, and does exploitation require an account?
Sites running the WordPress Ezoic plugin version 2.22.11 or earlier are affected. The issue is remotely exploitable without authentication or user interaction.
2
What is the expected security impact?
The supplied vector indicates high confidentiality impact, with no integrity or availability impact stated. It is rated high severity with a CVSS score of 7.5.