CVE-2026-22183 MEDIUM

CVE-2026-22183: wpDiscuz before 7.6.47 - Stored Cross-Site Scripting in Inline Comment Preview

Vendor Gvectors
Product wpDiscuz
Weakness CWE-79 · XSS
Published March 13, 2026
Last update March 13, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated users to inject malicious scripts by submitting comments with unescaped content. Attackers with unfiltered_html capabilities can inject JavaScript directly through comment content rendered in the AJAX response from the getLastInlineComments() function in class.WpdiscuzHelperAjax.php without proper HTML escaping.

Key dates

02Disclosure timeline

March 13, 2026 CVE published
March 13, 2026 Record updated

Related vulnerabilities

04Related CVE