216.73.216.233

CVE-2026-22182

· Published 13/03/2026 19:54 · Modified 13/03/2026 19:54

Labels: CVE-2026-22182 2026-03-13CVE-2026-22182CWE-862[email protected]

Essential information

Published
13/03/2026 19:54
Modified
13/03/2026 19:54
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the checkNotificationType() function. Attackers can repeatedly call the wpdiscuz-ajax.php endpoint with arbitrary postId and comment_id parameters to flood subscribers with notifications, as the handler lacks nonce verification, authentication checks, and rate limiting.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wpdiscuz / wpdiscuz cpe:2.3:a:wpdiscuz:wpdiscuz:<7.6.47:*:*:*:*:*:*:*

References