WP Clinic
Log in Sign up

CVE · Medium

CVE-2026-22183 — Comments – wpDiscuz [wpdiscuz] < 7.6.47

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-22183 Comments – wpDiscuz [wpdiscuz] < 7.6.47 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 7.6.47 7.6.47 2026-03-13

CVE-2026-22183

wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated users to inject malicious scripts by submitting comments with unescaped content. Attackers with unfiltered_html capabilities can inject JavaScript directly through comment content rendered in the AJAX response from the getLastInlineComments() function in class.WpdiscuzHelperAjax.php without proper HTML escaping.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.