WordPress security by component
Comments – wpDiscuz
Plugin description
Comments – wpDiscuz enhances WordPress comments with interactive discussion features, threaded replies, voting, subscriptions, and customizable comment forms.
Comments – wpDiscuz (wpdiscuz) is a WordPress plugin with 35 published CVE records in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 10.
Plugin slug:
wpdiscuzLatest vulnerability
CVE-2026-19704: wpDiscuz permits unauthenticated comment-query injection
wpDiscuz before 7.6.66 uses an unvalidated visitor-controlled value as SQL query grammar. An unauthenticated attacker can read comments awaiting moderation, marked as spam or trash, or attached to private and draft posts. The disclosed injection exposes those comment records rather than arbitrary database contents.
| Safe version |
|
||
|---|---|---|---|
| Sep 02, 2026 |
CVE-2026-19704
wpDiscuz permits unauthenticated comment-query injection
wpDiscuz before 7.6.66 uses an unvalidated visitor-controlled value as SQL query grammar. An unauthenticated attacker can read comments awaiting moderation, marked as spam or trash, or attached to private and draft posts. The disclosed injection exposes those comment records rather than arbitrary database contents.
|
7.6.66 |
CVE5.3
NVDPending
|
| Aug 07, 2026 |
CVE-2026-15032
wpDiscuz permits unauthenticated stored XSS through comment image URLs
Comments - wpDiscuz before 7.6.60 does not escape a user-supplied comment image URL before inserting it into an HTML attribute. An unauthenticated commenter can store a crafted URL whose script executes when anyone, including an Administrator, views the comment. The changelog identifies image-URL conversion and attribute output but not the request parameter, submission action, conversion function or exact attribute.
|
7.6.60 |
CVE6.1
NVDPending
|
| Jul 03, 2026 |
CVE-2026-9148
Comments – wpDiscuz: Cross-site scripting
Comments – wpDiscuz is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 7.6.56.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Mar 13, 2026 |
CVE-2026-22216
Wpdiscuz: A security weakness
Wpdiscuz is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.9
NVD5.3
|
| Mar 13, 2026 |
CVE-2026-22215
Wpdiscuz: Cross-site request forgery
Wpdiscuz is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.3
NVD5.4
|
| Mar 13, 2026 |
CVE-2026-22210
Wpdiscuz: Cross-site scripting
Wpdiscuz is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE2.1
NVD6.1
|
| Mar 13, 2026 |
CVE-2026-22209
Wpdiscuz: Cross-site scripting
Wpdiscuz is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.1
NVD4.8
|
| Mar 13, 2026 |
CVE-2026-22204
Wpdiscuz: A security weakness
Wpdiscuz is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVD5.3
|
| Mar 13, 2026 |
CVE-2026-22203
Wpdiscuz: Sensitive information exposure
Wpdiscuz is affected by sensitive information exposure. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE6.9
NVDPending
|
| Mar 13, 2026 |
CVE-2026-22202
Wpdiscuz: Cross-site request forgery
Wpdiscuz is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.1
NVD6.5
|
| Mar 13, 2026 |
CVE-2026-22201
Wpdiscuz: A security weakness
Wpdiscuz is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.9
NVDPending
|
| Mar 13, 2026 |
CVE-2026-22193
Wpdiscuz: SQL injection
Wpdiscuz is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.2
NVD7.5
|
| Mar 13, 2026 |
CVE-2026-22183
Wpdiscuz: Cross-site scripting
Wpdiscuz is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.3
NVD5.4
|
| Mar 13, 2026 |
CVE-2026-22182
Wpdiscuz: Denial of service
Wpdiscuz is affected by denial of service. The vulnerable path is reachable without authentication. A successful request can exhaust or disrupt the affected operation and make site functionality unavailable.
|
See mitigation notes |
CVE8.7
NVDPending
|
| Dec 30, 2025 |
CVE-2025-68997
wpDiscuz: A security weakness
wpDiscuz is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Sep 22, 2025 |
CVE-2025-59591
wpDiscuz: A security weakness
wpDiscuz is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jan 02, 2025 |
CVE-2023-46309
wpDiscuz: A security weakness
wpDiscuz is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD7.3
|
| Jan 02, 2025 |
CVE-2023-45760
wpDiscuz: A security weakness
wpDiscuz is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Oct 25, 2024 |
CVE-2024-9488
Comments – wpDiscuz: Privilege escalation or authentication bypass
Comments – wpDiscuz is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Aug 02, 2024 |
CVE-2024-6704
Comments – wpDiscuz: A security weakness
Comments – wpDiscuz is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD6.1
|
| Jun 08, 2024 |
CVE-2024-35681
wpDiscuz: Cross-site scripting
wpDiscuz is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jun 04, 2024 |
CVE-2023-46310
wpDiscuz: Cross-site scripting
wpDiscuz is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.3
NVD6.1
|
| Apr 23, 2024 |
CVE-2024-2477
wpDiscuz: Cross-site scripting
wpDiscuz is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Feb 01, 2024 |
CVE-2023-51691
Comments – wpDiscuz: Cross-site scripting
Comments – wpDiscuz is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Dec 20, 2023 |
CVE-2023-46311
Comments – wpDiscuz: A security weakness
Comments – wpDiscuz is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE2.7
NVD6.5
|
| Nov 22, 2023 |
CVE-2023-47775
Wpdiscuz: Cross-site request forgery
Wpdiscuz is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Nov 06, 2023 |
CVE-2023-47185
Wpdiscuz: Cross-site scripting
Wpdiscuz is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Oct 20, 2023 |
CVE-2023-3998
wpDiscuz: A security weakness
wpDiscuz is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Oct 20, 2023 |
CVE-2023-3869
wpDiscuz: A security weakness
wpDiscuz is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Nov 18, 2022 |
CVE-2022-43492
Wpdiscuz: Broken access control
Wpdiscuz is affected by broken access control. Exposure depends on how the affected operation is made reachable by the site. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Feb 21, 2022 |
CVE-2022-23984
Wpdiscuz: Sensitive information exposure
Wpdiscuz is affected by sensitive information exposure. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE3.7
NVD7.5
|
| Nov 08, 2021 |
CVE-2021-24806
wpDiscuz: Cross-site request forgery
wpDiscuz is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD4.3
|
| Oct 11, 2021 |
CVE-2021-24737
Comments – wpDiscuz: Cross-site scripting
Comments – wpDiscuz is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Aug 24, 2020 |
CVE-2020-24186
Wpdiscuz: Code execution
Wpdiscuz is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE10.0
NVD10.0
|
| Jun 18, 2020 |
CVE-2020-13640
Wpdiscuz: SQL injection
Wpdiscuz is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD9.8
|