CVE-2026-22192

Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localStorage values. Attackers can modify client-side authentication state to bypass server-side access controls and gain unauthorized access to protected management functionality without valid credentials.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gvectors:wpdiscuz:*:*:*:*:*:wordpress:*:*

History

22 Apr 2026, 19:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.1
v2 : unknown
v3 : 9.9
References
  • {'url': 'https://wordpress.org/plugins/wpdiscuz/', 'tags': ['Product'], 'source': 'disclosure@vulncheck.com'}
  • {'url': 'https://wordpress.org/plugins/wpdiscuz/#developers', 'tags': ['Product', 'Release Notes'], 'source': 'disclosure@vulncheck.com'}
  • {'url': 'https://www.vulncheck.com/advisories/wpdiscuz-before-stored-cross-site-scripting-via-malicious-options-import', 'tags': ['Third Party Advisory'], 'source': 'disclosure@vulncheck.com'}
  • () https://github.com/kmkz/Exploits/blob/master/2026/CVE-2026-22192-22199_Voltronic-Power_Preauth_root_RCE.txt -
  • () https://voltronicpower.com/ -
  • () https://www.boffsec-services.com/posts/sicuroweb-cve-2026-22191/ -
  • () https://www.vulncheck.com/advisories/voltronic-power-snmp-web-pro-authentication-bypass-via-localstorage -
Summary
  • (es) wpDiscuz anterior a la versión 7.6.47 contiene una vulnerabilidad de cross-site scripting almacenada que permite a atacantes autenticados inyectar JavaScript malicioso importando un archivo de opciones manipulado con valores de campo customCss sin escapar. Los atacantes pueden proporcionar un archivo de importación JSON malicioso que contiene cargas útiles de script en el parámetro customCss que se ejecutan en cada página cuando se renderizan a través del gestor de opciones sin una sanitización adecuada.
Summary (en) wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by importing a crafted options file with unescaped customCss field values. Attackers can supply a malicious JSON import file containing script payloads in the customCss parameter that execute on every page when rendered through the options handler without proper sanitization. (en) Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localStorage values. Attackers can modify client-side authentication state to bypass server-side access controls and gain unauthorized access to protected management functionality without valid credentials.
CWE CWE-79 CWE-306

17 Mar 2026, 20:28

Type Values Removed Values Added
References () https://wordpress.org/plugins/wpdiscuz/ - () https://wordpress.org/plugins/wpdiscuz/ - Product
References () https://wordpress.org/plugins/wpdiscuz/#developers - () https://wordpress.org/plugins/wpdiscuz/#developers - Product, Release Notes
References () https://www.vulncheck.com/advisories/wpdiscuz-before-stored-cross-site-scripting-via-malicious-options-import - () https://www.vulncheck.com/advisories/wpdiscuz-before-stored-cross-site-scripting-via-malicious-options-import - Third Party Advisory
CPE cpe:2.3:a:gvectors:wpdiscuz:*:*:*:*:*:wordpress:*:*
First Time Gvectors
Gvectors wpdiscuz

13 Mar 2026, 19:54

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-13 19:54

Updated : 2026-04-22 19:17


NVD link : CVE-2026-22192

Mitre link : CVE-2026-22192

CVE.ORG link : CVE-2026-22192


JSON object : View

Products Affected

gvectors

  • wpdiscuz
CWE
CWE-306

Missing Authentication for Critical Function