Beveiligingsadvies

CVE-2026-22204

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-03-13 01:18:11
Laatst bijgewerkt 2026-03-13 16:07:30
Toegewezen door VulnCheck
CVSS-score 6.3
Status PUBLISHED

Beschrijving

wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious data into the comment_author_email cookie. Attackers can craft a malicious cookie value that, when processed through urldecode() and passed to wp_mail() functions, enables header injection to alter email recipients or inject additional headers.