PT-2026-25142 · Gvectors · Wpdiscuz
Scott Moore
·
Publicado
2026-03-13
·
Atualizado
2026-03-13
·
CVE-2026-22202
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wpDiscuz versions prior to 7.6.47
Description
The software contains a cross-site request forgery issue that allows attackers to delete all comments associated with an email address. This is achieved by crafting a malicious GET request with a valid HMAC key. Attackers can embed the
deletecomments action URL in image tags or other resources to trigger permanent deletion of comments without user confirmation or POST-based CSRF protection. The vulnerable API endpoint is /deletecomments. The HMAC key is used to validate the request.Recommendations
Update wpDiscuz to version 7.6.47 or later.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wpdiscuz