CVE-2026-22183
wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated users to inject malicious scripts by submitting comments with unescaped content. Attackers with unfiltered_html capabilities can inject JavaScript directly through comment content rendered in the AJAX response from the getLastInlineComments() function in class.WpdiscuzHelperAjax.php without proper HTML escaping.
Vendor
Product
CWE
Yayın Tarihi
2026-03-13 19:54:07
Güncelleme
2026-03-17 20:28:54
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-