What is CVE-2026-18789?
CVE-2026-18789 is a vulnerability in the Ezoic WordPress plugin before version 2.23.1 where access to content export functionality is improperly restricted. This allows unauthenticated attackers to trigger a server-side export of the site's database, including user password hashes and password reset tokens. Users should immediately update the plugin to the latest patched version.
Azərbaycanca: CVE-2026-18789, Ezoic WordPress plagininin 2.23.1-dən əvvəlki versiyalarında məzmun ixrac funksiyası üzərində məhdudiyyətin olmamasıdır. Bu, autentifikasiya olunmamış hücumçulara saytın verilənlər bazasını, o cümlədən istifadəçi parol heşləri və şifrə sıfırlama tokenlərini ixrac etməyə imkan verir. İstifadəçilərə plaqini dərhal ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What risk does the CVE-2026-18789 vulnerability pose in the Ezoic plugin?
This vulnerability allows unauthenticated attackers to export the site's database, including user password hashes and password reset tokens.
To which version should I update to protect against CVE-2026-18789?
You should update the Ezoic plugin to at least version 2.23.1 or the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.