CVE-2026-22202

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments action URL in image tags or other resources to trigger permanent deletion of comments without user confirmation or POST-based CSRF protection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gvectors:wpdiscuz:*:*:*:*:*:wordpress:*:*

History

17 Jun 2026, 10:19

Type Values Removed Values Added
Summary
  • (es) wpDiscuz antes de 7.6.47 contiene una vulnerabilidad de falsificación de petición en sitios cruzados que permite a los atacantes eliminar todos los comentarios asociados a una dirección de correo electrónico mediante la creación de una petición GET maliciosa con una clave HMAC válida. Los atacantes pueden incrustar la URL de acción deletecomments en etiquetas de imagen u otros recursos para desencadenar la eliminación permanente de comentarios sin confirmación del usuario o protección CSRF basada en POST.

17 Mar 2026, 20:24

Type Values Removed Values Added
CPE cpe:2.3:a:gvectors:wpdiscuz:*:*:*:*:*:wordpress:*:*
First Time Gvectors
Gvectors wpdiscuz
References () https://wordpress.org/plugins/wpdiscuz/ - () https://wordpress.org/plugins/wpdiscuz/ - Product
References () https://wordpress.org/plugins/wpdiscuz/#developers - () https://wordpress.org/plugins/wpdiscuz/#developers - Product, Release Notes
References () https://www.vulncheck.com/advisories/wpdiscuz-before-destructive-get-action-deletes-all-comments-by-email - () https://www.vulncheck.com/advisories/wpdiscuz-before-destructive-get-action-deletes-all-comments-by-email - Third Party Advisory

13 Mar 2026, 19:54

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-13 19:54

Updated : 2026-06-17 10:19


NVD link : CVE-2026-22202

Mitre link : CVE-2026-22202

CVE.ORG link : CVE-2026-22202


JSON object : View

Products Affected

gvectors

  • wpdiscuz
CWE
CWE-352

Cross-Site Request Forgery (CSRF)