CVE · High

CVE-2026-9148 — Comments – wpDiscuz [wpdiscuz] < 7.6.57

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-9148 Comments – wpDiscuz [wpdiscuz] < 7.6.57 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 7.6.57 7.6.57 2026-07-02

CVE-2026-9148

The wpDiscuz plugin for WordPress versions 7.6.56 and earlier is susceptible to Stored Cross-Site Scripting due to inadequate output escaping. Specifically, the getCommentAuthor() function directly incorporates unescaped comment_author_url values into single-quoted HTML attributes, allowing attackers to inject malicious scripts that can be executed when users view affected pages.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.