CVE-2026-22216
A missing security check in WordPress plugin wpDiscuz prior to version 7.6.47 enables unverified individuals to register any email address for post notifications by sending a POST request to the class.WpdiscuzHelperAjax.php file's wpdAddSubscription handler. This vulnerability allows attackers to exploit wildcard characters in subscription queries, potentially matching multiple email addresses and triggering unwanted notification emails to unsuspecting account holders.
Based on public CVE data (MITRE/NVD).