← Retour aux CVEs
CVE-2026-22192
MEDIUM6.1
Description
wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by importing a crafted options file with unescaped customCss field values. Attackers can supply a malicious JSON import file containing script payloads in the customCss parameter that execute on every page when rendered through the options handler without proper sanitization.
Details CVE
Score CVSS v3.16.1
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurREQUIRED
Publie3/13/2026
Derniere modification3/17/2026
Sourcenvd
Observations honeypot0
Produits affectes
gvectors:wpdiscuz
Faiblesses (CWE)
CWE-79
References
https://wordpress.org/plugins/wpdiscuz/(disclosure@vulncheck.com)
https://wordpress.org/plugins/wpdiscuz/#developers(disclosure@vulncheck.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.