CVE-2026-22191

wpDiscuz before 7.6.47 contains a shortcode injection vulnerability that allows attackers to execute arbitrary shortcodes by including them in comment content sent via email notifications. Attackers can inject shortcodes like [contact-form-7] or [user_meta] in comments, which are executed server-side when the WpdiscuzHelperEmail class processes notifications through do_shortcode() before wp_mail().
Configurations

Configuration 1 (hide)

cpe:2.3:a:gvectors:wpdiscuz:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2026-03-13 19:54

Updated : 2026-03-23 17:06


NVD link : CVE-2026-22191

Mitre link : CVE-2026-22191

CVE.ORG link : CVE-2026-22191


JSON object : View

Products Affected

gvectors

  • wpdiscuz
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')