PT-2026-25146 · Gvectors · Wpdiscuz

Scott Moore

·

Published

2026-03-13

·

Updated

2026-03-13

·

CVE-2026-22210

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions wpDiscuz versions prior to 7.6.47
Description The software contains a cross-site scripting issue that allows attackers to inject malicious code. This is achieved through unescaped attachment URLs in HTML output, specifically by exploiting the WpdiscuzHelperUpload class. Attackers can create malicious attachment records or utilize filter hooks to inject arbitrary JavaScript into img and anchor tag attributes, leading to code execution within the context of WordPress users viewing comments.
Recommendations Update wpDiscuz to version 7.6.47 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-22210

Affected Products

Wpdiscuz