PT-2026-25142 · Gvectors · Wpdiscuz

Scott Moore

·

Publicado

2026-03-13

·

Atualizado

2026-03-13

·

CVE-2026-22202

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions wpDiscuz versions prior to 7.6.47
Description The software contains a cross-site request forgery issue that allows attackers to delete all comments associated with an email address. This is achieved by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments action URL in image tags or other resources to trigger permanent deletion of comments without user confirmation or POST-based CSRF protection. The vulnerable API endpoint is /deletecomments. The HMAC key is used to validate the request.
Recommendations Update wpDiscuz to version 7.6.47 or later.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22202

Produtos afetados

Wpdiscuz