LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-22215

gvectors · wpdiscuz

Published
CVSS4.3
Severitymedium
WeaknessCWE-352
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Description

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that allows attackers to trigger unauthorized actions without nonce validation. Attackers can craft malicious requests to enumerate follow relationships and manipulate user follow data by exploiting the missing CSRF protection in the follows page handler.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-22215

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-22215.