CVE · High

CVE-2026-22182 — Comments – wpDiscuz [wpdiscuz] < 7.6.47

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-22182 Comments – wpDiscuz [wpdiscuz] < 7.6.47 Allocation of Resources Without Limits or Throttling High 7.5 < 7.6.47 7.6.47 2026-03-13

CVE-2026-22182

A flaw in wpDiscuz versions prior to 7.6.47 allows unauthenticated users to cause a denial of service by triggering excessive notification emails. This is achieved through repeated calls to the wpdiscuz-ajax.php endpoint with manipulated postId and comment_id values, which are not properly validated or limited. As a result, subscribers can be overwhelmed with notifications due to the lack of nonce verification and rate limiting in the affected function.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.