LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-22182

gvectors · wpdiscuz

Published
CVSS7.5
Severityhigh
WeaknessCWE-862
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the checkNotificationType() function. Attackers can repeatedly call the wpdiscuz-ajax.php endpoint with arbitrary postId and comment_id parameters to flood subscribers with notifications, as the handler lacks nonce verification, authentication checks, and rate limiting.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-22182

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-22182.