Junglewise Threat Intelligence

CVE-2026-9148: advancedcoding wpDiscuz Stored XSS in guest Website field

CVE-2026-9148 · Severity: high · CVSS 7.2 · Published 2026-07-03

Vendors: gVectors Team.

Executive brief

The wpDiscuz plugin for WordPress, which provides an enhanced comment system for websites, contains a security flaw in its guest comment feature. An attacker can submit a malicious link in the 'Website' field that executes harmful code in the browsers of other visitors or site administrators. This could lead to unauthorized actions being performed on the site or the theft of sensitive session information.

Technical details

The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient output escaping in the getCommentAuthor() function. Specifically, the function interpolates the 'comment_author_url' value directly into single-quoted HTML attributes without utilizing protective functions like esc_url() or esc_attr(). This allows unauthenticated remote attackers to inject arbitrary web scripts via the 'Website' field during guest comment submission. The injected scripts are stored in the database and executed in the context of any user (including administrators) who visits the page where the comment is displayed. The issue is fixed in version 7.6.57.

Affected products

  • advancedcoding Comments – wpDiscuz up to, and including, 7.6.56

Timeline

  • 2026-07-03: disclosed
  • 2026-07-03: advisory

References