Impact
The Comments WordPress plugin does not correctly escape a user‑supplied image URL before displaying it in an HTML attribute. This flaw allows an unauthenticated attacker to store a malicious payload that executes in the browsers of any user who views the affected content, including site administrators. The result is a classic Stored XSS vulnerability (CWE-79) that can compromise confidentiality, integrity, and availability of the site and its users.
Affected Systems
wpDiscuz versions earlier than 7.6.60 are affected. Users of the plugin on WordPress installations should verify that they are not running a vulnerable build of the plugin.
Risk and Exploitability
This vulnerability can be exploited by anyone without requiring authentication, meaning attackers can inject the payload directly into the stored content. While the EPSS score is unavailable and the flaw is not listed in CISA’s KEV catalog, the high severity of Stored XSS and the ease of exploitation dictate a high risk posture. An attacker could steal session cookies, deface the site, or deliver further malicious content to site visitors.
OpenCVE Enrichment