CVE-2026-22201: wpDiscuz before 7.6.47 - IP Address Spoofing in getIP()
Published Mar 13, 2026
·Updated
wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban enforcement by trusting untrusted HTTP headers. Attackers can set HTTPCLIENTIP or HTTPXFORWARDEDFOR headers to spoof their IP address and circumvent security controls.
Affected Software
2 affected components
wpdiscuz<7.6.47
gVectors Wpdiscuz Wordpress<7.6.47
Event History
Mar 13, 2026
CVE Published
via MITRE·01:18 AM
Data Sourced
via MITRE·01:18 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:54 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-22201?
CVE-2026-22201 is considered a high severity vulnerability due to its potential to allow IP address spoofing.
2
How do I fix CVE-2026-22201?
To fix CVE-2026-22201, update wpDiscuz to version 7.6.47 or later.
3
What systems are affected by CVE-2026-22201?
CVE-2026-22201 affects all versions of wpDiscuz prior to 7.6.47.
4
What kind of attacks can CVE-2026-22201 enable?
CVE-2026-22201 can enable attackers to bypass IP-based rate limiting and bans.
5
Why is CVE-2026-22201 a concern for website security?
CVE-2026-22201 is a concern because it undermines the effectiveness of IP-based security measures.