CVE Alert: CVE-2026-22202 - gVectors - wpDiscuz - RedPacket Security

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by

RedPacket Security
CVE Alert: CVE-2026-22193 - gVectors - wpDiscuz - RedPacket Security

wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escaping in SQL

RedPacket Security
CVE Alert: CVE-2026-22182 - gVectors - wpDiscuz - RedPacket Security

wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by

RedPacket Security
CVE Alert: CVE-2026-28562 - gVectors Team - wpForo Forum - RedPacket Security

wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql()

RedPacket Security