CVE-2026-22202: Gvectors Wpdiscuz

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments action URL in image tags or other resources to trigger permanent deletion of comments without user confirmation or POST-based CSRF protection.

Affected products

  • Gvectors Wpdiscuz: before 7.6.47 (fixed in 7.6.47)

Published 2026-03-13. Last modified 2026-06-17.