Published on 15 August 2026
An unauthenticated attacker can export the entire database of affected WordPress websites – including password hashes and password reset tokens. That is exactly what a security advisory from 12 August 2026 describes regarding the vulnerability identified as CVE-2026-18789 in the widely used Ezoic plugin for WordPress. All versions prior to 2.23.1 are affected – and according to the official plugin directory, at least 10,000 active installations. Anyone using the plugin who has not yet updated should read this article to the end and then act immediately.
On 12 August 2026, a security advisory was published documenting a serious vulnerability in the Ezoic plugin for WordPress. Ezoic is a service that helps websites manage and optimise advertising; the associated WordPress plugin integrates these functions directly into the website.
The core of the problem: in the affected versions, an attacker can – without having to log in first – misuse parts of the plugin's so-called content export function. This function is actually intended to output a website's content in an orderly fashion. Because of the flaw, however, it can be repurposed to trigger a server-side export of the entire website database.
By "server-side" we mean that the export is generated directly on the website's server – exactly where all the sensitive data resides. And that is precisely what makes the matter so serious: such a database export can contain far more than just public blog posts.
A WordPress database is the heart of every website. It contains practically everything: posts, pages, settings – but also the user accounts. And this is where the real risk of this vulnerability lies.
According to the security advisory, the triggered export can contain, among other things, the following sensitive data:
In addition, the advisory describes that the vulnerability allows certain plugin settings to be permanently altered. This means an attacker could not only siphon off data but also manipulate the website's configuration, without ever having possessed a valid login.
Particularly critical is the fact that the attack requires no login. Vulnerabilities that can only be exploited by logged-in users are already problematic – but those that any anonymous visitor from the internet can trigger are incomparably more dangerous. They can be exploited automatically and on a large scale, without the attacker having to overcome any hurdles first.
The vulnerability was classified with a severity of "high" and carries the official identifier CVE-2026-18789. CVE stands for "Common Vulnerabilities and Exposures" – an internationally uniform numbering system for known security flaws that enables experts to refer unambiguously to the same vulnerability.
Affected are websites that have the Ezoic WordPress Plugin installed in a version prior to 2.23.1. According to the figures from the official WordPress plugin directory, that amounts to at least 10,000 active installations. The actual number may be higher, since the directory only shows a lower estimate.
If you use the Ezoic plugin – for example because you display advertising on your website via the Ezoic service – you potentially belong to the group of those affected. The decisive factor is the installed version number.
The check is done within a few minutes. Proceed as follows:
Important: even if a plugin is deactivated but still installed, you should check it. Security flaws can under certain circumstances be exploited even in plugins that have not been fully removed. Deactivated but unneeded plugins should generally be deleted.
The most important measure is clear: update the plugin to version 2.23.1 or higher. According to the advisory, the vulnerability was fixed in this version. Proceed as follows:
Because the export, according to the advisory, can contain password hashes and reset tokens, we recommend – regardless of whether an attack on your website can be proven – the following additional precautions:
Whether the vulnerability is already being actively exploited is, based on the available material, unknown. That is no reason to sound the all-clear, however: as soon as a flaw is publicly documented, the likelihood increases that attackers will begin to specifically search for vulnerable websites. Act promptly, therefore, and do not wait.
This vulnerability affects not only the technical security of your website but can also have data protection consequences. Because a database export generally contains personal data – such as usernames, email addresses and the aforementioned password hashes.
Under the General Data Protection Regulation (GDPR), you as a website operator are obliged to protect personal data through appropriate technical and organisational measures. This explicitly includes the prompt installation of security updates.
If unauthorised access to personal data does actually occur – for example because an attacker has exported the database – a reporting obligation may apply. In principle, such a data breach must be reported to the competent supervisory authority within 72 hours of becoming known. Under certain circumstances, the affected individuals must also be informed.
Our recommendation from a GDPR perspective: after the update, carefully check whether there are any indications of an actual data leak. If signs of an unauthorised export can be found, bring in expert support early on in order to fulfil the reporting obligations correctly and on time. Also document when you installed the update and which protective measures you took – this documentation can be important in an emergency.
The combination of factors makes this vulnerability a case that should not be put on the back burner:
At the same time, there is a clear solution: a simple plugin update to version 2.23.1 or higher closes the flaw. Experience shows that the window between the publication of a vulnerability and the first automated attack attempts is short. That is precisely why, in such cases, speed counts.
With CVE-2026-18789, a highly rated vulnerability in the Ezoic plugin for WordPress became known on 12 August 2026 that allows unauthenticated attackers to export the database of affected websites – including password hashes and password reset tokens – as well as to permanently alter certain plugin settings. All versions prior to 2.23.1 are affected, and thus at least 10,000 active installations.
Check now whether you are using the Ezoic plugin, and update it immediately to version 2.23.1 or higher. Supplement the update with reset passwords, enabled two-factor authentication and a review of your plugin settings. At the same time, treat the incident as a possible data protection case and document your approach. Whether the flaw is already being actively exploited is currently unknown – that is no reason to wait. Those who act quickly close the door before anyone walks through it.
Source: security advisory of 12 August 2026, freshysites.com (Security Bulletin on CVE-2026-18789).