Junglewise Threat Intelligence

CVE-2026-32481: Ezoic broken authentication in WordPress plugin

CVE-2026-32481 · Severity: high · CVSS 7.5 · Published 2026-08-18

Executive brief

Ezoic is a WordPress plugin that integrates advertising and content optimization services into WordPress sites. A broken authentication vulnerability in versions 2.22.11 and earlier allows attackers to bypass the plugin's login system and gain unauthorized access without valid credentials, potentially compromising site administration and customer data.

Technical details

This vulnerability is a broken authentication flaw affecting Ezoic WordPress plugin versions up to 2.22.11. The vulnerability allows unauthenticated attackers to bypass authentication mechanisms, enabling them to log in as arbitrary users or administrators without providing correct credentials. The attack requires only network access to the affected WordPress site—no prior authentication is needed. An attacker exploiting this can gain full administrative control over the WordPress installation. The vulnerability is patched in version 2.23.1 and later.

Affected products

  • Ezoic Ezoic <= 2.22.11

Timeline

  • 2026-08-18: disclosed
  • 2026-08-14: patched: Patched in version 2.23.1
  • 2026-05-29: reported

References