Comment License

Comment License has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Comment License has a vendor fix available, so running the current release closes it.

All of these findings were reported by Daniel Ruf. Comment License is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.0.14.

Strategic Overview

Avg CVSSHigh
8.8/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Comment License vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2022-1957

Comment License <= 1.3.0 - Cross-Site Request Forgery to Settings Update

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv1.4.1

Comment License

Crowd Favorite

Author

Crowd Favorite

0.0(0)
0/100
Last Updated
2022-07-08 (4y ago)
Active Installs
30+
Downloads
16,447
Requires WP
1.5+
Requires PHP
0+
Tested up to
WP 6.0.14
Created
2007-02-26 (20y ago)

Comment License shows a license with terms of your choosing in your comments form. You can edit the terms of your license in the options page.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C