LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-22183

gvectors · wpdiscuz

Published
CVSS6.1
Severitymedium
WeaknessCWE-79
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated users to inject malicious scripts by submitting comments with unescaped content. Attackers with unfiltered_html capabilities can inject JavaScript directly through comment content rendered in the AJAX response from the getLastInlineComments() function in class.WpdiscuzHelperAjax.php without proper HTML escaping.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-22183

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-22183.