CVE · Medium

CVE-2026-22201 — Comments – wpDiscuz [wpdiscuz] < 7.6.47

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-22201 Comments – wpDiscuz [wpdiscuz] < 7.6.47 Use of Less Trusted Source Medium 5.3 < 7.6.47 7.6.47 2026-03-13

CVE-2026-22201

A flaw in wpDiscuz versions prior to 7.6.47 allows malicious users to manipulate their apparent IP address, thereby evading rate limiting measures and blocking rules by exploiting the getIP() function's reliance on unverified HTTP request headers. This vulnerability can be triggered by setting specific HTTP headers such as HTTP_CLIENT_IP or HTTP_X_FORWARDED_FOR. As a result, security controls that rely on IP addresses may be circumvented.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.