Advanced Comment Form
Advanced Comment Form has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 5.5 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Advanced Comment Form has a vendor fix available, so running the current release closes it.
All of these findings were reported by Asif Nawaz Minhas. Advanced Comment Form is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.
CVE-2022-3220Advanced Comment Form <= 1.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Advanced Comment Form
Author
Rock Solid
Advanced Comment Form enables you to customize the WordPress comment form right from your dashboard. You can find the settings page under Comments > Comment Form in the dashboard. Remove Fields remove the email field for standard, and non standard comment forms remove the website field for standard, and non standard comment forms Change Text remove the message that emails are not published and which fields are required remove the text about which html tags are allowed insert custom text before the form insert custom text after the form Layouts use a two columns layout for the comment form Shortcode [comment-form] shortcode to insert comment form into posts and pages Important Notes the plugin works only, if your theme uses the standard WordPress comment form function options that where submitted with the comment_form function in your template overwrite most of the plugin functions
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C