PT-2026-25143 · Gvectors · Wpdiscuz

Scott Moore

·

Publicado

2026-03-13

·

Atualizado

2026-03-13

·

CVE-2026-22203

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions wpDiscuz versions prior to 7.6.47
Description The software contains an information disclosure issue that can lead to the exposure of OAuth secrets. Administrators may unintentionally reveal OAuth secrets when exporting plugin options as JSON. Attackers could obtain exported files containing plaintext API secrets, including fbAppSecret, googleClientSecret, and twitterAppSecret, from sources like support tickets, backups, or version control repositories.
Recommendations Update wpDiscuz to version 7.6.47 or later.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22203

Produtos afetados

Wpdiscuz