Impact
The vulnerability allows an unauthenticated attacker to trigger a server‑side export of the site's database through improperly restricted REST routes in the Ezoic WordPress plugin. This results in the disclosure of user password hashes, reset tokens, and potentially other sensitive data that could be leveraged for credential stuffing or further attacks. The flaw also permits attackers to persistently alter certain plugin settings, which can lead to configuration drift and additional attack surfaces. The weakness is an example of improper access control, fitting CWE‑284. The impact extends to the confidentiality of user data and the integrity of site configuration.
Affected Systems
All installations of the Ezoic WordPress plugin earlier than version 2.23.1 are affected. The vulnerability is present in the WordPress plugin developed by Ezoic, specifically versions older than 2.23.1.
Risk and Exploitability
CVSS metrics are not disclosed in the public data, but the potential for data exposure and configuration vandalism suggests a high risk. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, indicating that no known field‑test exploits have been reported. Nevertheless, because the attack requires no authentication and the export endpoint is reachable via typical REST URLs, the likelihood of exploitation remains significant in environments where the plugin is active and no additional access controls are in place. The attack vector is inferred to be remote, through the exposed REST API endpoints.
OpenCVE Enrichment