CVE-2026-22182

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
13/03/2026
Last modified:
17/03/2026

Description

wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the checkNotificationType() function. Attackers can repeatedly call the wpdiscuz-ajax.php endpoint with arbitrary postId and comment_id parameters to flood subscribers with notifications, as the handler lacks nonce verification, authentication checks, and rate limiting.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gvectors:wpdiscuz:*:*:*:*:*:wordpress:*:* 7.6.47 (excluding)