Ezoic <= 2.22.11 - Authentication Bypass
critical
The Ezoic plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.22.11. This makes it possible for unauthenticated attackers to bypass authentication and access higher privileged accounts.
- CVSS:
- 9.8
- Affected:
- up to 2.22.11
- Fixed in:
- 2.23.1
- Disclosed:
- Aug 14, 2026
CVE-2026-32481 on NVD →
Ezoic <= 2.23.0 - Missing Authorization
medium
The Ezoic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.23.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.23.0
- Fixed in:
- 2.23.1
- Disclosed:
- Aug 10, 2026
CVE-2026-18789 on NVD →
Ezoic <= 2.8.8 - Missing Authorization to Stored Cross-Site Scripting
critical
The Ezoic plugin for WordPress is vulnerable to authorization bypass to stored cross-site scripting via several REST-API endpoints in versions up to, and including, 2.8.8 due to missing capability checks and insufficient input sanitization and output escaping. This makes it possible for unauthenticated-level attackers...
- CVSS:
- 9.8
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.9
- Disclosed:
- Nov 17, 2022
CVE-2022-41132 on NVD →
Ezoic <= 2.8.8 - Authenticated (Admin+) Stored Cross-Site Scripting
high
The Ezoic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions up to, and including, 2.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative privileges, to inject malicious web scripts into a page.
- CVSS:
- 7.2
- Affected:
- up to 2.8.8
- Fixed in:
- 2.8.9
- Disclosed:
- Nov 17, 2022
CVE-2022-41315 on NVD →
Ezoic [ezoic-integration] < 2.8.9
unknown
[en] Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability in Ezoic plugin <= 2.8.8 on WordPress.
- Affected:
- up to 2.8.9
- Fixed in:
- 2.8.9
- Disclosed:
- Nov 17, 2022
CVE-2022-41132 on NVD →
Ezoic [ezoic-integration] < 2.8.9
unknown
[en] Auth. Stored Cross-Site Scripting (XSS) vulnerability in Ezoic plugin <= 2.8.8 on WordPress.
- Affected:
- up to 2.8.9
- Fixed in:
- 2.8.9
- Disclosed:
- Nov 17, 2022
CVE-2022-41315 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database