Vulnerability Description
wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through unescaped attachment URLs in HTML output by exploiting the WpdiscuzHelperUpload class. Attackers can craft malicious attachment records or filter hooks to inject arbitrary JavaScript into img and anchor tag attributes, executing code in the context of WordPress users viewing comments.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gvectors | Wpdiscuz | < 7.6.47 |
Related Weaknesses (CWE)
References
- https://wordpress.org/plugins/wpdiscuz/Product
- https://wordpress.org/plugins/wpdiscuz/#developersProductRelease Notes
- https://www.vulncheck.com/advisories/wpdiscuz-before-cross-site-scripting-via-unThird Party Advisory
FAQ
What is CVE-2026-22210?
CVE-2026-22210 is a vulnerability with a CVSS score of 4.4 (MEDIUM). wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through unescaped attachment URLs in HTML output by exploiting the WpdiscuzHelperUpl...
How severe is CVE-2026-22210?
CVE-2026-22210 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-22210?
Check the references section above for vendor advisories and patch information. Affected products include: Gvectors Wpdiscuz.