CVE · Medium

CVE-2026-22216 — Comments – wpDiscuz [wpdiscuz] < 7.6.47

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-22216 Comments – wpDiscuz [wpdiscuz] < 7.6.47 Improper Control of Interaction Frequency Medium 5.3 < 7.6.47 7.6.47 2026-03-13

CVE-2026-22216

A missing security check in WordPress plugin wpDiscuz prior to version 7.6.47 enables unverified individuals to register any email address for post notifications by sending a POST request to the class.WpdiscuzHelperAjax.php file's wpdAddSubscription handler. This vulnerability allows attackers to exploit wildcard characters in subscription queries, potentially matching multiple email addresses and triggering unwanted notification emails to unsuspecting account holders.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.