CVE-2026-22199 is a vote manipulation vulnerability present in wpDiscuz versions prior to 7.6.47. Attackers can exploit this by obtaining fresh nonces and bypassing rate limiting through client-controlled headers, such as varying User-Agent or using IP rotation, to cast multiple votes. Rated Medium severity (CVSS 5.3), it has a network attack vector and low attack complexity, requiring no privileges or user interaction, with a low integrity impact limited to vote manipulation. There is currently no evidence of active exploitation, public exploit code is unavailable, and community discussion or media coverage is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.6.47CPE matchmatch criteria | cpe:2.3:a:gvectors:wpdiscuz:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.