Low severity3.7NVD Advisory· Published Mar 13, 2026· Updated Jun 17, 2026
CVE-2026-22204
CVE-2026-22204
Description
wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious data into the comment_author_email cookie. Attackers can craft a malicious cookie value that, when processed through urldecode() and passed to wp_mail() functions, enables header injection to alter email recipients or inject additional headers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- www.vulncheck.com/advisories/wpdiscuz-before-unsanitized-cookie-email-used-as-wp-mail-recipientnvdThird Party Advisory
- wordpress.org/plugins/wpdiscuz/nvdProduct
- wordpress.org/plugins/wpdiscuz/nvdProductRelease Notes
News mentions
0No linked articles in our index yet.