CVE-2026-22215

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that allows attackers to trigger unauthorized actions without nonce validation. Attackers can craft malicious requests to enumerate follow relationships and manipulate user follow data by exploiting the missing CSRF protection in the follows page handler.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gvectors:wpdiscuz:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2026-03-13 19:54

Updated : 2026-03-17 11:44


NVD link : CVE-2026-22215

Mitre link : CVE-2026-22215

CVE.ORG link : CVE-2026-22215


JSON object : View

Products Affected

gvectors

  • wpdiscuz
CWE
CWE-352

Cross-Site Request Forgery (CSRF)