PT-2026-25147 · Gvectors · Wpdiscuz
Scott Moore
·
Publicado
2026-03-13
·
Atualizado
2026-03-13
·
CVE-2026-22215
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
wpDiscuz versions prior to 7.6.47
Description
wpDiscuz is susceptible to a cross-site request forgery issue in the
getFollowsPage() function. The absence of nonce validation allows attackers to perform unauthorized actions. Specifically, malicious requests can be created to enumerate follow relationships and manipulate user follow data due to the missing CSRF protection in the follows page handler.Recommendations
Update wpDiscuz to version 7.6.47 or later.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wpdiscuz