← volver
CVE-2026-22202

wpDiscuz before 7.6.47 - Destructive GET Action Deletes All Comments by Email

CVSS 6.1 MEDIUMEPSS 0.2%CWE-352
wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments action URL in image tags or other resources to trigger permanent deletion of comments without user confirmation or POST-based CSRF protection.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
gVectors · wpDiscuz

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →