CVE-2026-22183: Gvectors Wpdiscuz

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated users to inject malicious scripts by submitting comments with unescaped content. Attackers with unfiltered_html capabilities can inject JavaScript directly through comment content rendered in the AJAX response from the getLastInlineComments() function in class.WpdiscuzHelperAjax.php without proper HTML escaping.

Affected products

  • Gvectors Wpdiscuz: before 7.6.47 (fixed in 7.6.47)

Published 2026-03-13. Last modified 2026-06-17.