CVE Database /
CVE-2026-22182
CVE · High
CVE-2026-22182 — Comments – wpDiscuz [wpdiscuz] < 7.6.47
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-22182
|
Comments – wpDiscuz [wpdiscuz] < 7.6.47 |
Allocation of Resources Without Limits or Throttling |
High
7.5
|
< 7.6.47
|
7.6.47 |
2026-03-13 |
—
|
CVE-2026-22182
wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the checkNotificationType() function. Attackers can repeatedly call the wpdiscuz-ajax.php endpoint with arbitrary postId and comment_id parameters to flood subscribers with notifications, as the handler lacks nonce verification, authentication checks, and rate limiting.
Source:
CVE.org
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings