CRITICAL🇵🇱 Wersja polska

CVE-2026-22193

CVSS 9.2v4.0pub. 2026-03-13upd. 2026-03-17

wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escaping in SQL queries. Attackers can inject malicious SQL code through email, activation_key, subscription_date, and imported_from parameters to manipulate database queries and extract sensitive information.

🤖 AI Analysis
How it works

Parameters passed to the getAllSubscriptions() function — including email, activation_key, subscription_date, and imported_from — are not properly escaped before being used in SQL queries. An attacker can inject malicious SQL code through any of these parameters, thereby manipulating the logic of queries executed on the database. Since the attack does not require authentication or user interaction, it can be carried out remotely over the network.

Impact

An attacker can extract sensitive data from the WordPress database, including user data, passwords, or configurations. Depending on database permissions, data modification or deletion is also possible, which could lead to complete takeover of the application.

Mitigation & patch

The wpDiscuz plugin should be immediately updated to version 7.6.47 or newer. The update is available in the WordPress repository at wordpress.org/plugins/wpdiscuz/. Until the patch is applied, it is recommended to consider temporarily disabling the plugin or restricting access to subscription-handling endpoints at the Web Application Firewall (WAF) level.

Who is affected

WordPress wpDiscuz plugin (Gvectors) in versions before 7.6.47

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Gvectors Wpdiscuz

    APP
    Gvectors
    < 7.6.47
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2024-9488CRITICAL9.8PL ✓same product

Authentication bypass w pluginie wpDiscuz dla WordPress (do wersji 7.6.24)

CVE-2020-24186CRITICAL10.0PL ✓same product

RCE poprzez nieautoryzowany upload plików PHP w wtyczce WordPress wpDiscuz

CVE-2020-13640CRITICAL9.8PL ✓same product

SQL injection w pluginie wpDiscuz dla WordPress (wersje ≤ 5.3.5)

CVE-2026-22182HIGH8.7same product

wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users...

CVE-2026-22192HIGH8.8same product

Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthent...