VYPR

Wpdiscuz

by Gvectors

CVEs (33)

  • CVE-2026-22203MedMar 13, 2026
    risk 0.32cvss 4.9epss 0.00

    wpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertently expose OAuth secrets by exporting plugin options as JSON. Attackers can obtain exported files containing plaintext API secrets like fbAppSecret,…

  • CVE-2021-24737MedOct 11, 2021
    risk 0.31cvss 4.8epss 0.01

    The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html…

  • CVE-2026-22210MedMar 13, 2026
    risk 0.29cvss 4.4epss 0.00

    wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through unescaped attachment URLs in HTML output by exploiting the WpdiscuzHelperUpload class. Attackers can craft malicious attachment records or filter hooks to…

  • CVE-2026-22209MedMar 13, 2026
    risk 0.29cvss 5.5epss 0.00

    wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators to inject malicious scripts by breaking out of style tags. Attackers with admin access can inject payloads like in the custom…

  • CVE-2026-22215MedMar 13, 2026
    risk 0.28cvss 4.3epss 0.00

    wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that allows attackers to trigger unauthorized actions without nonce validation. Attackers can craft malicious requests to enumerate follow relationships and manipulate…

  • CVE-2023-45760MedJan 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.3.

  • CVE-2023-47775MedNov 22, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions.

  • CVE-2022-43492MedNov 18, 2022
    risk 0.28cvss 4.3epss 0.01

    Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.

  • CVE-2021-24806MedNov 8, 2021
    risk 0.28cvss 4.3epss 0.00

    The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers…

  • CVE-2024-6704MedAug 2, 2024
    risk 0.27cvss 5.3epss 0.01

    The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of filtering of HTML tags in comments. This makes it possible for unauthenticated attackers to add HTML such as hyperlinks to…

  • CVE-2026-22204LowMar 13, 2026
    risk 0.24cvss 3.7epss 0.00

    wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious data into the comment_author_email cookie. Attackers can craft a malicious cookie value that, when processed through urldecode() and…

  • CVE-2022-23984LowFeb 21, 2022
    risk 0.24cvss 3.7epss 0.01

    Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11).

  • CVE-2023-46311LowDec 20, 2023
    risk 0.18cvss 2.7epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a through 7.6.3.

Page 2 of 2