Advanced Comment Form

Advanced Comment Form has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 5.5 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Advanced Comment Form has a vendor fix available, so running the current release closes it.

All of these findings were reported by Asif Nawaz Minhas. Advanced Comment Form is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.

Strategic Overview

Avg CVSSMedium
5.5/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Advanced Comment Form vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.5CVE-2022-3220

Advanced Comment Form <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Advanced Comment Form banner
Latestv1.2.3

Advanced Comment Form

Rock Solid

Author

Rock Solid

5.0(19)
100/100
Last Updated
2024-06-06 (2y ago)
Active Installs
4,000+
Downloads
73,249
Requires WP
6.0+
Requires PHP
7.2+
Tested up to
WP 6.5.10
Created
2014-06-23 (12y ago)

Advanced Comment Form enables you to customize the WordPress comment form right from your dashboard. You can find the settings page under Comments > Comment Form in the dashboard. Remove Fields remove the email field for standard, and non standard comment forms remove the website field for standard, and non standard comment forms Change Text remove the message that emails are not published and which fields are required remove the text about which html tags are allowed insert custom text before the form insert custom text after the form Layouts use a two columns layout for the comment form Shortcode [comment-form] shortcode to insert comment form into posts and pages Important Notes the plugin works only, if your theme uses the standard WordPress comment form function options that where submitted with the comment_form function in your template overwrite most of the plugin functions

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C