CVE-2026-22202
MEDIUM WAF: Low
CVSS 6.5
Published: 2026-03-13
CWE-352
wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments action URL in image tags or other resources to trigger permanent deletion of comments without user confirmation or POST-based CSRF protection.
WAF Coverage Analysis
Cross-Site Request Forgery (CSRF)
Low WAF Coverage
OWASP: A01:2021 Broken Access Control
Affected Software
| Vendor | Product | Version |
|---|---|---|
| gvectors | wpdiscuz | up to 7.6.47 |
References
- wordpress.org (Product)
- wordpress.org (Product, Release Notes)
- www.vulncheck.com (Third Party Advisory)