What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments woodiscuz-woocommerce-comments allows Stored XSS.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.2.9.
Explanation of Vulnerability in Simple Terms
02Summary
WooDiscuz allows stored cross-site scripting (XSS) attacks through comment fields. An authenticated user with high privileges can inject malicious scripts that execute in other users' browsers when they view comments. The attack requires user interaction—victims must view the affected comment. Impact is limited to low-severity data theft or session hijacking.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts into comments that run in other users' browsers.
Potential impact on your site
04Site Impact
Trusted users with editor/admin roles can compromise other users' sessions or steal data via comment injection.
Conditions required to exploit
05Prerequisites
Attacker must have high-level WordPress privileges (e.g., editor or admin) and the victim must view the malicious comment.
Key dates
06Disclosure timeline
May 28, 2023
CVE published
April 28, 2026
Record updated