PT-2026-25146 · Gvectors · Wpdiscuz
Scott Moore
·
Published
2026-03-13
·
Updated
2026-03-13
·
CVE-2026-22210
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
wpDiscuz versions prior to 7.6.47
Description
The software contains a cross-site scripting issue that allows attackers to inject malicious code. This is achieved through unescaped attachment URLs in HTML output, specifically by exploiting the
WpdiscuzHelperUpload class. Attackers can create malicious attachment records or utilize filter hooks to inject arbitrary JavaScript into img and anchor tag attributes, leading to code execution within the context of WordPress users viewing comments.Recommendations
Update wpDiscuz to version 7.6.47 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpdiscuz