
🚨 HIGH - wpDiscuz stored XSS via guest “Website” field (CVE-2026-9148) CVE-2026-9148 is a stored cross-site scripting flaw in the wpDiscuz WordPress plugin, specifically in getCommentAuthor() when rendering the guest commenter “Website” (comment_author_url) value. The root cause is insufficient output escaping/improper sanitization of user-controlled input injected into HTML attributes. An unauthenticated attacker can submit a crafted comment with a malicious Website URL payload, which is stored and later executed when any user (including admins) views the affected page. Successful exploitation can lead to session hijacking, admin account takeover via CSRF-like actions, content manipulation, and broader site compromise. 👉 Affected: wpDiscuz <= 7.6.56 | Upgrade to No fix yet — treat as suspicious
Post summary
The post announces a newly disclosed stored XSS vulnerability in wpDiscuz (CVE-2026-9148) with detailed technical information and notes that no patch is yet available.
