Loading
wpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertently expose OAuth secrets by exporting plugin options as JSON. Attackers can obtain exported files containing plaintext API secrets like fbAppSecret, googleClientSecret, twitterAppSecret, and other social login credentials from support tickets, backups, or version control repositories.
Use CWE-200, Gvectors vendor hub and Wpdiscuz product page to widen CVE-2026-22203 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-22193, CVE-2026-22192 and CVE-2026-22199 for nearby disclosures in the same product family.