cvedb.io
CVE-2026-22203
MEDIUM · CVSS 4.9
EPSS exploitation probability: 0%
Published 2026-03-13T19:54:10.580 · Last modified 2026-06-17T10:19:32.503

Summary

wpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertently expose OAuth secrets by exporting plugin options as JSON. Attackers can obtain exported files containing plaintext API secrets like fbAppSecret, googleClientSecret, twitterAppSecret, and other social login credentials from support tickets, backups, or version control repositories.

Affected products

gvectors — wpdiscuz

Does this affect you?

Add your gear to cvedb and we'll alert you only when gvectors ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.