VYPR

Comments

by WordPress

Source repositories

CVEs (6)

  • CVE-2024-2404MedApr 24, 2024
    risk 0.35cvss 5.4epss 0.00

    The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow low privilege users such as Subscribers to perform Stored Cross-Site Scripting attacks.

  • CVE-2024-2402MedApr 24, 2024
    risk 0.35cvss 5.4epss 0.00

    The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2025-13820MedJan 1, 2026
    risk 0.34cvss 5.3epss 0.00

    The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.

  • CVE-2024-12874MedMay 15, 2025
    risk 0.31cvss 4.8epss 0.00

    The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

  • CVE-2022-3909MedDec 5, 2022
    risk 0.31cvss 4.8epss 0.01

    The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

  • CVE-2024-6704MedAug 2, 2024
    risk 0.27cvss 5.3epss 0.01

    The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of filtering of HTML tags in comments. This makes it possible for unauthenticated attackers to add HTML such as hyperlinks to…