LIVE · cybersecurity feed
Live wire
cve recordlow

CVE-2026-22204

gvectors · wpdiscuz

Published
CVSS3.7
Severitylow
WeaknessCWE-20
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Description

wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious data into the comment_author_email cookie. Attackers can craft a malicious cookie value that, when processed through urldecode() and passed to wp_mail() functions, enables header injection to alter email recipients or inject additional headers.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-22204

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-22204.