PT-2026-25142 · Gvectors · Wpdiscuz

·

CVE-2026-22202

·

Published

2026-03-13

·

Updated

2026-03-13

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions wpDiscuz versions prior to 7.6.47
Description The software contains a cross-site request forgery issue that allows attackers to delete all comments associated with an email address. This is achieved by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments action URL in image tags or other resources to trigger permanent deletion of comments without user confirmation or POST-based CSRF protection. The vulnerable API endpoint is /deletecomments. The HMAC key is used to validate the request.
Recommendations Update wpDiscuz to version 7.6.47 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22202

Affected Products

Wpdiscuz