wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators to inject malicious scripts by breaking out of style tags. Attackers with admin access can inject payloads like </style><script>alert(1)</script> in the custom CSS setting to execute arbitrary JavaScript in user browsers.
References
Configurations
History
No history.
Information
Published : 2026-03-13 19:54
Updated : 2026-03-26 19:16
NVD link : CVE-2026-22209
Mitre link : CVE-2026-22209
CVE.ORG link : CVE-2026-22209
JSON object : View
Products Affected
gvectors
- wpdiscuz
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
