CVE-2026-15032 PUBLISHED

wpDiscuz < 7.6.60 - Unauthenticated Stored XSS via Image URL Conversion

Assigner: WPScan
Reserved: 08.07.2026 Published: 07.08.2026 Updated: 07.08.2026

The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store a Cross-Site Scripting payload that executes in the browser of any user, including administrators, who views the affected content.

Product Status

Vendor Unknown
Product Comments
Versions Default: unaffected
  • affected from 0 to 7.6.60 (excl.)

Credits

  • hieus finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE