๐Ÿ” CVE Alert

CVE-2026-15032

UNKNOWN 0.0

wpDiscuz < 7.6.60 - Unauthenticated Stored XSS via Image URL Conversion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store a Cross-Site Scripting payload that executes in the browser of any user, including administrators, who views the affected content.

Vendor unknown
Product comments
Published Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for unknown comments

Be the first to know when new unknown vulnerabilities affecting unknown comments are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Comments
0 < 7.6.60

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/e77ea3fb-4d38-4fa7-a50b-1a0078f34474/

Credits

hieus WPScan