LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-22216

gvectors · wpdiscuz

Published
CVSS6.5
Severitymedium
WeaknessCWE-799
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Description

wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to subscribe arbitrary email addresses to post notifications by sending POST requests to the wpdAddSubscription handler in class.WpdiscuzHelperAjax.php. Attackers can exploit LIKE wildcard characters in the subscription query to match multiple email addresses and generate unwanted notification emails to victim accounts.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-22216

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-22216.