Comments – wpDiscuz
wpdiscuz · eklenti
Comments – wpDiscuz için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.
30 bilinen açık
3 kritik · 19 kayıt giriş yapmadan sömürülebilir · 1 kayıt için istismar kodu yayımlanmış · son kayıt 3 Tem 2026
wordpress.org'da yayında · son sürüm 7.6.71 · son güncelleme 16 Eyl 2026 · 60 bin+ kurulum
wordpress.org durumu 2 Eki 2026 tarihinde kontrol edildi
Güvenlik açıkları
- Kritik 9.8
CVE-2024-9488kimlik doğrulamasız≤ 7.6.24
Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider
- Kritik 9.8
CVE-2020-13640kimlik doğrulamasız
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL comma
- Kritik 9.2
CVE-2026-22193kimlik doğrulamasız→ 7.6.47
wpDiscuz before 7.6.47 - SQL Injection in getAllSubscriptions()
- Yüksek 8.8
CVE-2023-47775kimlik doğrulamasız · tıklama gerekir≤ 7.6.11
WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Request Forgery (CSRF)
- Yüksek 8.8
CVE-2023-45760giriş gerekir≤ 7.6.3
WordPress wpDiscuz plugin <= 7.6.3 - Broken Access Control vulnerability
- Yüksek 8.8
CVE-2022-43492abone+
WordPress Comments – wpDiscuz plugin 7.4.2 - Auth. Insecure Direct Object References (IDOR) vulnerability
- Yüksek 8.7
CVE-2026-22182kimlik doğrulamasız→ 7.6.47
wpDiscuz before 7.6.47 - Unauthenticated Email Notification Flood via wpdCheckNotificationType
- Yüksek 7.5
CVE-2022-23984kimlik doğrulamasız≤ 7.3.11
WordPress wpDiscuz plugin <= 7.3.11 - Sensitive Information Disclosure
- Yüksek 7.3
CVE-2023-46309kimlik doğrulamasız≤ 7.6.10
WordPress wpDiscuz plugin <= 7.6.10 - Broken Access Control vulnerability
- Yüksek 7.2
CVE-2026-9148kimlik doğrulamasız≤ 7.6.56
Comments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website' Field
- Orta 6.9
CVE-2026-22216kimlik doğrulamasız→ 7.6.47
wpDiscuz before 7.6.47 - No Rate Limiting on Subscription Endpoints with LIKE Wildcard Bypass
- Orta 6.9
CVE-2026-22201kimlik doğrulamasız→ 7.6.47
wpDiscuz before 7.6.47 - IP Address Spoofing in getIP()
- Orta 6.9
CVE-2026-22203yüksek yetki→ 7.6.47
wpDiscuz before 7.6.47 - Options Export Leaks OAuth Secrets in Plaintext
- Orta 6.5
CVE-2023-46311yüksek yetki≤ 7.6.3
WordPress wpDiscuz Plugin <= 7.6.3 is vulnerable to Insecure Direct Object References (IDOR)
- Orta 6.3
CVE-2026-22204kimlik doğrulamasız→ 7.6.47
wpDiscuz before 7.6.47 - Unsanitized Cookie Email Used as wp_mail() Recipient
- Orta 6.1
CVE-2026-22202kimlik doğrulamasız · tıklama gerekir→ 7.6.47
wpDiscuz before 7.6.47 - Destructive GET Action Deletes All Comments by Email
- Orta 6.1
CVE-2024-6704kimlik doğrulamasız≤ 7.6.21
Comments – wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection
- Orta 6.1
CVE-2023-46310kimlik doğrulamasız≤ 7.6.10
WordPress wpDiscuz plugin <= 7.6.10 - Content Injection vulnerability
- Orta 6.1
CVE-2023-47185kimlik doğrulamasız · tıklama gerekir≤ 7.6.11
WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Scripting (XSS)
- Orta 5.4
CVE-2024-35681giriş gerekir≤ 7.6.18
WordPress wpDiscuz plugin <= 7.6.18 - Cross Site Scripting (XSS) vulnerability
- Orta 5.4
CVE-2024-2477yazar+≤ 7.6.15
wpDiscuz <= 7.6.15 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Alternative Text
- Orta 5.3
CVE-2026-22215kimlik doğrulamasız · tıklama gerekir→ 7.6.47
wpDiscuz before 7.6.47 - Missing CSRF Protection on wpdGetFollowsPage
- Orta 5.3
CVE-2025-68997kimlik doğrulamasız≤ 7.6.43
WordPress wpDiscuz plugin <= 7.6.43 - Insecure Direct Object References (IDOR) vulnerability
- Orta 5.3
CVE-2023-3998kimlik doğrulamasız≤ 7.6.3
wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Post Rating Increase/Decrease
- Orta 5.3
CVE-2023-3869kimlik doğrulamasız≤ 7.6.3
wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Comment Rating Increase/Decrease
- Orta 5.3
CVE-2026-22183giriş gerekir→ 7.6.47
wpDiscuz before 7.6.47 - Stored Cross-Site Scripting in Inline Comment Preview
- Orta 5.1
CVE-2026-22209yönetici→ 7.6.47
wpDiscuz before 7.6.47 - Cross-Site Scripting via Unescaped Custom CSS in Style Tag
- Orta 4.8
CVE-2023-51691yüksek yetki≤ 7.6.12
WordPress wpDiscuz Plugin <= 7.6.12 is vulnerable to Cross Site Scripting (XSS)
- Orta 4.3
CVE-2025-59591giriş gerekir≤ 7.6.33
WordPress wpDiscuz Plugin <= 7.6.33 - Broken Access Control Vulnerability
- Düşük 2.1
CVE-2026-22210giriş gerekir→ 7.6.47
wpDiscuz before 7.6.47 - Cross-Site Scripting via Unescaped Attachment URLs
Yetki etiketi kaydın kendi metninden okunur (ör. “abone+”: abone ve üstü roller). Metin rol söylemiyorsa CVSS'e göre “giriş gerekir” ya da “yüksek yetki” yazılır; rol adı uydurulmaz. “Tıklama gerekir”: saldırı, oturumu açık birinin bağlantıya tıklamasına bağlı (CSRF, yansıyan XSS).