PT-2026-71027 · WordPress · Ezoic
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ezoic WordPress plugin versions prior to 2.23.1
Description
Insufficient access restrictions in the content export functionality allow unauthenticated attackers to trigger a server-side export of the site database. This exposure includes sensitive data such as user password hashes and password reset tokens. Additionally, attackers can persistently modify certain plugin settings.
Recommendations
Update the Ezoic WordPress plugin to version 2.23.1 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ezoic