PT-2026-25147 · Gvectors · Wpdiscuz
Scott Moore
·
Published
2026-03-13
·
Updated
2026-03-13
·
CVE-2026-22215
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
wpDiscuz versions prior to 7.6.47
Description
wpDiscuz is susceptible to a cross-site request forgery issue in the
getFollowsPage() function. The absence of nonce validation allows attackers to perform unauthorized actions. Specifically, malicious requests can be created to enumerate follow relationships and manipulate user follow data due to the missing CSRF protection in the follows page handler.Recommendations
Update wpDiscuz to version 7.6.47 or later.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpdiscuz