Unrated severityNVD Advisory· Published Mar 13, 2026· Updated Mar 13, 2026
wpDiscuz before 7.6.47 - Stored Cross-Site Scripting in Inline Comment Preview
CVE-2026-22183
Description
wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated users to inject malicious scripts by submitting comments with unescaped content. Attackers with unfiltered_html capabilities can inject JavaScript directly through comment content rendered in the AJAX response from the getLastInlineComments() function in class.WpdiscuzHelperAjax.php without proper HTML escaping.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- wordpress.org/plugins/wpdiscuz/mitrepatch
- www.vulncheck.com/advisories/wpdiscuz-before-stored-cross-site-scripting-in-inline-comment-previewmitrethird-party-advisory
- wordpress.org/plugins/wpdiscuz/mitreproduct
News mentions
0No linked articles in our index yet.