PT-2026-25139 · Gvectors · Wpdiscuz

·

CVE-2026-22193

·

Published

2026-03-13

·

Updated

2026-03-13

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wpDiscuz versions prior to 7.6.47
Description wpDiscuz versions prior to 7.6.47 contain an SQL injection issue in the getAllSubscriptions() function. String parameters are not properly escaped in SQL queries, allowing attackers to inject malicious SQL code. The parameters susceptible to injection are email, activation key, subscription date, and imported from. Successful exploitation could allow attackers to manipulate database queries and extract sensitive information. It is estimated that over 100,000 WordPress sites running wpDiscuz are potentially affected.
Recommendations Update wpDiscuz to version 7.6.47 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22193

Affected Products

Wpdiscuz