Ad

CVE-2026-22202

MEDIUM CVSS 4.0: 6.1 EPSS 0.02%
Updated Mar 17, 2026
Gvectors
Parameter Value
CVSS 6.1 (MEDIUM)
Affected Versions before 7.6.47
Fixed In 7.6.47
Type CWE-352 (Cross-Site Request Forgery (CSRF))
Vendor Gvectors
Public PoC No

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments action URL in image tags or other resources to trigger permanent deletion of comments without user confirmation or POST-based CSRF protection.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Gvectors Wpdiscuz
cpe:2.3:a:gvectors:wpdiscuz:*:*:*:*:*:wordpress:*:*
7.6.47