Loading
wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escaping in SQL queries. Attackers can inject malicious SQL code through email, activation_key, subscription_date, and imported_from parameters to manipulate database queries and extract sensitive information.
Use CWE-89, Gvectors vendor hub and Wpdiscuz product page to widen CVE-2026-22193 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-22192, CVE-2026-22199 and CVE-2026-22216 for nearby disclosures in the same product family.