CVE-2026-9148Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAuthor() function, which interpolates the stored comment_author_url value directly into single-quoted HTML attributes without applying esc_url() or esc_attr(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-03: 1Technical Details · 2026-07-03: 107-03
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - wpDiscuz stored XSS via guest “Website” field (CVE-2026-9148) CVE-2026-9148 is a stored cross-site scripting flaw in the wpDiscuz WordPress plugin, specifically in getCommentAuthor() when rendering the guest commenter “Website” (comment_author_url) value. The root cause is insufficient output escaping/improper sanitization of user-controlled input injected into HTML attributes. An unauthenticated attacker can submit a crafted comment with a malicious Website URL payload, which is stored and later executed when any user (including admins) views the affected page. Successful exploitation can lead to session hijacking, admin account takeover via CSRF-like actions, content manipulation, and broader site compromise. 👉 Affected: wpDiscuz <= 7.6.56 | Upgrade to No fix yet — treat as suspicious

    Post summary

    The post announces a newly disclosed stored XSS vulnerability in wpDiscuz (CVE-2026-9148) with detailed technical information and notes that no patch is yet available.

    0000085
    236 followersView on X

Explore more