CVE-2026-22210
Published
CVSS v3
4.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through unescaped attachment URLs in HTML output by exploiting the WpdiscuzHelperUpload class. Attackers can craft malicious attachment records or filter hooks to inject arbitrary JavaScript into img and anchor tag attributes, executing code in the context of WordPress users viewing comments.
<p>wpDiscuz is an advanced AJAX-powered WordPress comments plugin that upgrades the default WordPress comment system with live commenting, comment voting, inline feedback, social login, custom comment forms, and modern engagement-focused features.</p>
<p>Perfect as a modern Disqus alternative while keeping all comments stored securely in your own WordPress database.</p>
<p>Designed to supercharge WordPress native comments, wpDiscuz delivers a fast, lightweight, and highly interactive commenting experience for blogs, news websites, magazines, communities, membership sites, and WooCommerce stores.</p>
<p>wpDiscuz version 7 introduces a revolutionary approach to WordPress commenting with innovative engagement tools, optimized AJAX performance, lazy-loaded comments, and a modern responsive design.</p>
<ul>
<li>wpDiscuz Demo: <a href="https://wpdiscuz.com/" rel="nofollow ugc">https://wpdiscuz.com/</a></li>
<li>Support Forum: <a href="https://wpdiscuz.com/community/" rel="nofollow ugc">https://wpdiscuz.com/community/</a></li>
<li>wpDiscuz GDPR: <a href="https://wpdiscuz.com/gdpr/" rel="nofollow ugc">https://wpdiscuz.com/gdpr/</a></li>
<li>wpDiscuz Addons: <a href="https://wpdiscuz.com/addons/" rel="nofollow ugc">https://wpdiscuz.com/addons/</a></li>
<li>wpDiscuz Documentation: <a href="https://wpdiscuz.com/docs/" rel="nofollow ugc">https://wpdiscuz.com/docs/</a></li>
<li>wpDiscuz Addons Bundle: <a href="https://gvectors.com/product/wpdiscuz-addons-bundle/" rel="nofollow ugc">https://gvectors.com/product/wpdiscuz-addons-bundle/</a></li>
</ul>
<h4>Live AJAX Comments</h4>
<p>Enable fast AJAX-powered live comments for WordPress with instant comment posting, smooth interactions, and real-time updates without page reloads.</p>
<h4>Inline Commenting and Feedback</h4>
<p>Allow users to comment directly on post content and provide inline feedback for better discussions and higher user engagement.</p>
<h4>Comment Voting and Rating</h4>
<p>Boost community interaction with upvote/downvote comment voting, comment rating, and post rating features.</p>
<h4>Social Login and Social Comments</h4>
<p>Allow users to comment using popular social login providers like Facebook and Twitter for a faster commenting experience.</p>
<h4>Custom WordPress Comment Forms</h4>
<p>Create custom comment forms and fields for different post types, products, pages, communities, and discussions.</p>
<h4>WooCommerce Comment Integration</h4>
<p>Improve WooCommerce product discussions and customer engagement with modern AJAX-powered product comments and rating features.</p>
<h4>Fast and Lightweight WordPress Comments</h4>
<p>wpDiscuz is optimized for speed with lazy-loaded comments, built-in caching, AJAX posting, and performance-focused architecture.</p>
<h4>Disqus Alternative for WordPress</h4>
<p>Replace Disqus, Jetpack Comments, and other third-party comment systems while keeping full ownership of your comments and user data.</p>
<h4>Comments – wpDiscuz Features</h4>
<ul>
<li>Three modern WordPress comment layouts</li>
<li>Fast AJAX-powered WordPress comments</li>
<li>Interactive live comment form for WordPress</li>
<li>Inline commenting and inline feedback</li>
<li>Live notifications with real-time comment bubble updates</li>
<li>Social commenting with multiple social login options</li>
<li>Post rating and comment rating features</li>
<li>Responsive WordPress comment forms and comment threads</li>
<li>Modern user interface and user experience</li>
<li>Comment sorting by newest, oldest, and most voted comments</li>
<li>Anonymous WordPress comments support</li>
<li>Integration with social network login plugins</li>
<li>Multi-level nested comment threads</li>
<li>AJAX “Load More Comments” button</li>
<li>Lazy load WordPress comments on scroll</li>
<li>WordPress date format integration</li>
<li>Comment editing for logged-in users and guests</li>
<li>Automatic URL and image embedding in comments</li>
<li>Long comment collapsing with “Read More” button</li>
<li>Comment subscription and notification options</li>
<li>AJAX comment form validation and posting</li>
<li>Fully integrated with WordPress native comments</li>
<li>Secure anti-spam WordPress comment system</li>
<li>Positive and negative comment voting</li>
<li>Smart voting system with cookies and user tracking</li>
<li>Quick Tags support for comments</li>
<li>Custom WordPress comment forms and custom fields</li>
<li>Highlighting new comments since last visit</li>
<li>Notifications when comments are approved</li>
<li>View replies button for nested comments</li>
<li>Comment access control by user roles</li>
<li>Option to load all comments on first page load</li>
<li>Built-in Gravatar caching</li>
<li>Sticky comments support</li>
<li>Closed comment threads support</li>
<li>User follow and subscriptions</li>
<li>Built-in comment and author caching system</li>
</ul>
<h4>Add-ons</h4>
<ul>
<li>| <a href="https://gvectors.com/product/wpdiscuz-addons-bundle/" rel="nofollow ugc">wpDiscuz – Bundle</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-reviews/" rel="nofollow ugc">wpDiscuz – Reviews</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-emoticons/" rel="nofollow ugc">wpDiscuz – Emoticons</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-user-notifications/" rel="nofollow ugc">wpDiscuz – User Notifications</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-media-uploader/" rel="nofollow ugc">wpDiscuz – Media Uploader</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-embeds/" rel="nofollow ugc">wpDiscuz – Embeds</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-comment-author-info/" rel="nofollow ugc">wpDiscuz – Comment Author Info</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-recaptcha/" rel="nofollow ugc">wpDiscuz – Google ReCaptcha</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-mycred/" rel="nofollow ugc">wpDiscuz – myCRED Integration</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-widgets/" rel="nofollow ugc">wpDiscuz – Widgets</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-frontend-moderation/" rel="nofollow ugc">wpDiscuz – Front-end Moderation</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-subscribe-manager/" rel="nofollow ugc">wpDiscuz – Subscription Manager</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-comment-search/" rel="nofollow ugc">wpDiscuz – Comment Search</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-report-flagging/" rel="nofollow ugc">wpDiscuz – Comment Report and Flagging</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-ads-manager/" rel="nofollow ugc">wpDiscuz – Ads Manager</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-user-comment-mentioning/" rel="nofollow ugc">wpDiscuz – User & Comment Mentioning</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-advanced-likers/" rel="nofollow ugc">wpDiscuz – Advanced Likers</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-online-users/" rel="nofollow ugc">wpDiscuz – Online Users</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-private-comments/" rel="nofollow ugc">wpDiscuz – Private Comments</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-syntax-highlighter/" rel="nofollow ugc">wpDiscuz – Syntax Highlighter</a></li>
<li>| <a href="https://gvectors.com/product/comments-censure-pro/" rel="nofollow ugc">Comments Censure PRO</a></li>
</ul>
<h4>Integration Add-ons</h4>
<ul>
<li>| <a href="https://gvectors.com/product/wpdiscuz-buddypress-integration/" rel="nofollow ugc">wpDiscuz – BuddyPress Integration</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-giphy-integration/" rel="nofollow ugc">wpDiscuz – GIPHY Integration</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-voice-commenting/" rel="nofollow ugc">wpDiscuz – Voice Commenting</a></li>
</ul>