PT-2026-25139 · Gvectors · Wpdiscuz

Scott Moore

·

Published

2026-03-13

·

Updated

2026-03-13

·

CVE-2026-22193

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wpDiscuz versions prior to 7.6.47
Description wpDiscuz versions prior to 7.6.47 contain an SQL injection issue in the getAllSubscriptions() function. String parameters are not properly escaped in SQL queries, allowing attackers to inject malicious SQL code. The parameters susceptible to injection are email, activation key, subscription date, and imported from. Successful exploitation could allow attackers to manipulate database queries and extract sensitive information. It is estimated that over 100,000 WordPress sites running wpDiscuz are potentially affected.
Recommendations Update wpDiscuz to version 7.6.47 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-22193

Affected Products

Wpdiscuz