CVE-2026-22183 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated users to injec…
Medium CVSS: 5.3

CVE-2026-22183

wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated users to inject malicious scripts by submitting comments with unescaped content. Attackers with unfiltered_html capabilities can inject JavaScript directly through comment content rendered in the AJAX response from the getLastInlineComments() function in class.WpdiscuzHelperAjax.php without proper HTML escaping.
Vendor
Gvectors
Product
Wpdiscuz
CWE
CWE-79
Yayın Tarihi
2026-03-13 19:54:07
Güncelleme
2026-03-17 20:28:54
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar