CVE-2026-22192Disclosure(gvectors / wpdiscuz)

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for gvectors wpdiscuz systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localStorage values. Attackers can modify client-side authentication state to bypass server-side access controls and gain unauthorized access to protected management functionality without valid credentials.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wpdiscuz

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-13); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
wpdiscuz

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-13: 1Mentions · 2026-04-22: 1Mentions · 2026-06-30: 1PoC Mentioned / Linked · 2026-04-22: 1PoC Mentioned / Linked · 2026-06-30: 1Exploit Tool / Code · 2026-04-22: 1Technical Details · 2026-03-13: 1Technical Details · 2026-04-22: 1Technical Details · 2026-06-30: 103-1304-2206-30
Signal classification2 categories
Disclosure
266.7%
Exploit
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-131
Disclosure1
2026-04-221
Exploit1
2026-06-301
Disclosure1
Full discourse3 posts
  • kmkz@kmkz_security
    Exploit

    Update: dropped CVE-2026-22191:SSTI-> sandbox escape-> JS exec (No user interaction) CVE-2026-22192+22199: Voltronic UPS preauth root RCE chain Exposed: direct pivot into infra!🔥 Write-up https://www.boffsec-services.com/posts/sicuroweb-cve-2026-22191/ POC https://github.com/kmkz/Exploits/tree/master/2026 🫡to @catc0n & @VulnCheckAI support!

    Post summary

    The post announces CVE‑2026‑22191 and CVE‑2026‑22192/22199, provides a PoC and exploit code on GitHub, and details the exploitation chain, but offers no evidence of active exploitation or a patch.

    1220823814.7K
    19.6K followersView on X
  • kmkz@kmkz_security
    Disclosure

    I underplayed this one: so I fixed it ! Voltronic Power SNMP Web Pro : CVE-2026-22192 + CVE-2026-22199 / CVSS 10.0 > In a nutshell: Client-side auth bypass, pre-auth path traversal, /etc/shadow, offline crack, SSH root on an industrial UPS. Just another trusted crappy box in the rack becoming the perfect initial access inside the plant(s). 👉Details: https://tinyurl.com/upsremoteroot Kind of things (and way more!) we will talk about during #BSidesOT / ICS #Paris 2026 : Join us ! #OTSecurity #ICS #OffensiveSecurity

    Post summary

    The post discloses two critical CVEs affecting Voltronic Power UPS, describing an auth bypass and path traversal that can yield root SSH access, while linking to additional details but providing no exploit code or evidence of active attacks.

    030801.1K
    19.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22192 wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by importing a crafted … https://www.cve.org/CVERecord?id=CVE-2026-22192

    Post summary

    The post announces CVE-2026-22192, a stored XSS flaw in wpDiscuz versions prior to 7.6.47 that permits authenticated attackers to inject malicious JavaScript via crafted imports. No PoC, exploit, active exploitation, or patch information is provided.

    00000112
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgvectorswpdiscuz-wordpress-

Explore more