PT-2026-2166 · Voltronic Power+1 · Snmp Web Pro+1
Jean-Marie Bourbon
+2
·
Published
2026-01-09
·
Updated
2026-04-22
·
CVE-2026-22192
CVSS v3.1
9.9
Critical
| AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
wpDiscuz versions prior to 7.6.47
Description
The software contains a stored cross-site scripting issue that permits authenticated attackers to inject malicious JavaScript. This is achieved by importing a specially crafted options file containing unescaped custom CSS field values. Attackers can provide a malicious JSON import file with script payloads within the
customCss parameter. These payloads execute on every page when rendered through the options handler due to insufficient sanitization.Recommendations
Update wpDiscuz to version 7.6.47 or later.
Exploit
Fix
Missing Authentication
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snmp Web Pro
Wpdiscuz