CVE Database /
CVE-2026-22201
CVE · Medium
CVE-2026-22201 — Comments – wpDiscuz [wpdiscuz] < 7.6.47
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-22201
|
Comments – wpDiscuz [wpdiscuz] < 7.6.47 |
Use of Less Trusted Source |
Medium
5.3
|
< 7.6.47
|
7.6.47 |
2026-03-13 |
—
|
CVE-2026-22201
A flaw in wpDiscuz versions prior to 7.6.47 allows malicious users to manipulate their apparent IP address, thereby evading rate limiting measures and blocking rules by exploiting the getIP() function's reliance on unverified HTTP request headers. This vulnerability can be triggered by setting specific HTTP headers such as HTTP_CLIENT_IP or HTTP_X_FORWARDED_FOR. As a result, security controls that rely on IP addresses may be circumvented.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings