Skip to content
Noroxi

Comments – wpDiscuz

wpdiscuz · plugin

Known security vulnerabilities for Comments – wpDiscuz. Find out in seconds which version runs on your site with WP Lens.

30 known vulnerabilities

3 critical · 19 exploitable without logging in · 1 with public exploit code · latest Jul 3, 2026

Listed on wordpress.org · latest 7.6.71 · last updated Sep 16, 2026 · 60K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2024-9488unauthenticated≤ 7.6.24

    Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider

    Critical 9.8
  • CVE-2020-13640unauthenticated

    A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL comma

    Critical 9.8
  • CVE-2026-22193unauthenticated→ 7.6.47

    wpDiscuz before 7.6.47 - SQL Injection in getAllSubscriptions()

    Critical 9.2
  • CVE-2023-47775unauthenticated · needs a click≤ 7.6.11

    WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Request Forgery (CSRF)

    High 8.8
  • CVE-2023-45760login required≤ 7.6.3

    WordPress wpDiscuz plugin <= 7.6.3 - Broken Access Control vulnerability

    High 8.8
  • CVE-2022-43492subscriber+

    WordPress Comments – wpDiscuz plugin 7.4.2 - Auth. Insecure Direct Object References (IDOR) vulnerability

    High 8.8
  • CVE-2026-22182unauthenticated→ 7.6.47

    wpDiscuz before 7.6.47 - Unauthenticated Email Notification Flood via wpdCheckNotificationType

    High 8.7
  • CVE-2022-23984unauthenticated≤ 7.3.11

    WordPress wpDiscuz plugin <= 7.3.11 - Sensitive Information Disclosure

    High 7.5
  • CVE-2023-46309unauthenticated≤ 7.6.10

    WordPress wpDiscuz plugin <= 7.6.10 - Broken Access Control vulnerability

    High 7.3
  • CVE-2026-9148unauthenticated≤ 7.6.56

    Comments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website' Field

    High 7.2
  • CVE-2026-22216unauthenticated→ 7.6.47

    wpDiscuz before 7.6.47 - No Rate Limiting on Subscription Endpoints with LIKE Wildcard Bypass

    Medium 6.9
  • CVE-2026-22201unauthenticated→ 7.6.47

    wpDiscuz before 7.6.47 - IP Address Spoofing in getIP()

    Medium 6.9
  • CVE-2026-22203high privilege→ 7.6.47

    wpDiscuz before 7.6.47 - Options Export Leaks OAuth Secrets in Plaintext

    Medium 6.9
  • CVE-2023-46311high privilege≤ 7.6.3

    WordPress wpDiscuz Plugin <= 7.6.3 is vulnerable to Insecure Direct Object References (IDOR)

    Medium 6.5
  • CVE-2026-22204unauthenticated→ 7.6.47

    wpDiscuz before 7.6.47 - Unsanitized Cookie Email Used as wp_mail() Recipient

    Medium 6.3
  • CVE-2026-22202unauthenticated · needs a click→ 7.6.47

    wpDiscuz before 7.6.47 - Destructive GET Action Deletes All Comments by Email

    Medium 6.1
  • CVE-2024-6704unauthenticated≤ 7.6.21

    Comments – wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection

    Medium 6.1
  • CVE-2023-46310unauthenticated≤ 7.6.10

    WordPress wpDiscuz plugin <= 7.6.10 - Content Injection vulnerability

    Medium 6.1
  • CVE-2023-47185unauthenticated · needs a click≤ 7.6.11

    WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Scripting (XSS)

    Medium 6.1
  • CVE-2024-35681login required≤ 7.6.18

    WordPress wpDiscuz plugin <= 7.6.18 - Cross Site Scripting (XSS) vulnerability

    Medium 5.4
  • CVE-2024-2477author+≤ 7.6.15

    wpDiscuz <= 7.6.15 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Alternative Text

    Medium 5.4
  • CVE-2026-22215unauthenticated · needs a click→ 7.6.47

    wpDiscuz before 7.6.47 - Missing CSRF Protection on wpdGetFollowsPage

    Medium 5.3
  • CVE-2025-68997unauthenticated≤ 7.6.43

    WordPress wpDiscuz plugin <= 7.6.43 - Insecure Direct Object References (IDOR) vulnerability

    Medium 5.3
  • CVE-2023-3998unauthenticated≤ 7.6.3

    wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Post Rating Increase/Decrease

    Medium 5.3
  • CVE-2023-3869unauthenticated≤ 7.6.3

    wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Comment Rating Increase/Decrease

    Medium 5.3
  • CVE-2026-22183login required→ 7.6.47

    wpDiscuz before 7.6.47 - Stored Cross-Site Scripting in Inline Comment Preview

    Medium 5.3
  • CVE-2026-22209admin→ 7.6.47

    wpDiscuz before 7.6.47 - Cross-Site Scripting via Unescaped Custom CSS in Style Tag

    Medium 5.1
  • CVE-2023-51691high privilege≤ 7.6.12

    WordPress wpDiscuz Plugin <= 7.6.12 is vulnerable to Cross Site Scripting (XSS)

    Medium 4.8
  • CVE-2025-59591login required≤ 7.6.33

    WordPress wpDiscuz Plugin <= 7.6.33 - Broken Access Control Vulnerability

    Medium 4.3
  • CVE-2026-22210login required→ 7.6.47

    wpDiscuz before 7.6.47 - Cross-Site Scripting via Unescaped Attachment URLs

    Low 2.1

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory