CVE-2026-15032: wpDiscuz < 7.6.60 - Unauthenticated Stored XSS via Image URL Conversion
The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store a Cross-Site Scripting payload that executes in the browser of any user, including administrators, who views the affected content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress wpDiscuzto a version that resolves this vulnerability.Fixed in 7.6.60Patch wpDiscuz < 7.6.60 - Unauthenticated Stored XSS via Image URL Conversion
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15032?
CVE-2026-15032 has a risk rating of 62, indicating medium severity.
How do I fix CVE-2026-15032?
To fix CVE-2026-15032, update the wpDiscuz plugin to version 7.6.60 or higher.
What type of vulnerability is CVE-2026-15032?
CVE-2026-15032 is an unauthenticated stored Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-15032?
CVE-2026-15032 affects any website using wpDiscuz versions prior to 7.6.60.
When was CVE-2026-15032 published?
CVE-2026-15032 was published on August 7, 2026.