Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localStorage values. Attackers can modify client-side authentication state to bypass server-side access controls and gain unauthorized access to protected management functionality without valid credentials.
References
Configurations
History
22 Apr 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.9 |
| References |
|
|
| Summary |
|
|
| Summary | (en) Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localStorage values. Attackers can modify client-side authentication state to bypass server-side access controls and gain unauthorized access to protected management functionality without valid credentials. | |
| CWE | CWE-306 |
17 Mar 2026, 20:28
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://wordpress.org/plugins/wpdiscuz/ - Product | |
| References | () https://wordpress.org/plugins/wpdiscuz/#developers - Product, Release Notes | |
| References | () https://www.vulncheck.com/advisories/wpdiscuz-before-stored-cross-site-scripting-via-malicious-options-import - Third Party Advisory | |
| CPE | cpe:2.3:a:gvectors:wpdiscuz:*:*:*:*:*:wordpress:*:* | |
| First Time |
Gvectors
Gvectors wpdiscuz |
13 Mar 2026, 19:54
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-13 19:54
Updated : 2026-04-22 19:17
NVD link : CVE-2026-22192
Mitre link : CVE-2026-22192
CVE.ORG link : CVE-2026-22192
JSON object : View
Products Affected
gvectors
- wpdiscuz
CWE
CWE-306
Missing Authentication for Critical Function
