CVE-2026-22202: wpDiscuz before 7.6.47 - Destructive GET Action Deletes All Comments by Email
wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments action URL in image tags or other resources to trigger permanent deletion of comments without user confirmation or POST-based CSRF protection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22202?
The severity of CVE-2026-22202 is considered high due to its potential to allow unauthorized deletion of comments.
How do I fix CVE-2026-22202?
To fix CVE-2026-22202, upgrade wpDiscuz to version 7.6.47 or later.
What type of vulnerability is CVE-2026-22202?
CVE-2026-22202 is a cross-site request forgery (CSRF) vulnerability.
What can attackers do with CVE-2026-22202?
Attackers can delete all comments associated with a specified email address through a malicious GET request.
Which versions of wpDiscuz are affected by CVE-2026-22202?
wpDiscuz versions before 7.6.47 are affected by CVE-2026-22202.