Decent Comments
Decent Comments has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 7.5, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).
The one issue recorded for Decent Comments has a vendor fix available, so running the current release closes it.
All of these findings were reported by Vaibhav Narkhede. Decent Comments is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-7385Decent Comments < 3.0.2 - Unauthenticated Information Exopsure
Read the full analysisVulnerability Records

Decent Comments
Author
itthinx
Decent Comments shows what people say. The Decent Comments plugin helps you show comments on your site in a neat way. It lets you display comments along with avatars of the people who wrote them and previews of what they said. This makes your site more engaging for visitors. If you want to show comments along with their author’s avatars and an excerpt of their comment, recent comments on any of your posts, posts from certain categories and other criteria … then this might just be the right plugin for you. The plugin provides configurable blocks, widgets, shortcodes and an API to display comments in sensible ways. This includes author avatars, links, comment excerpts … Anywhere you place comments, by means of its block, widget, shortcode or by using its API, you can: Show an excerpt or the full comment. You can choose to not show the comment as well. Determine the number of words shown for excerpts. Set your kind of ellipsis. Set the number of comments to show. Show the author’s avatar and determine its size. Sort by author email, author URL, content (what’s said in the comment), date, karma or post … in ascending or descending order. Show comments for the current post or for a specific post. Show comments for a specific post type. Show comments for posts in specific categories, for specific tags, … (more precisely: the ability to show comments from posts related to one or more terms in a chosen taxonomy). Show comments for a set of posts and/or excluding a set of posts. and more to come … got suggestions? Visit the Documentation pages for details. Feedback is welcome. If you need help, have problems, want to leave feedback or want to provide constructive criticism, please do so at the Decent Comments plugin page. Please try to solve problems there before you rate this plugin or say it doesn’t work. There goes a lot of work into providing you with free quality plugins! Please appreciate that and help with your feedback. Thanks! Follow @itthinx on X, @itthinx on Mastodon, @itthinx on Reddit for news and updates on this and other plugins and tools. Translations Catalan translation provided by Ibidem Group Chinese translation provided by Francesco from in Cina French translation provided by Thomas Mur from Creapage.net German translation provided by the author itthinx Italian translation provided by Francesco from in Cina Lithuanian translation provided by Vincent G from Host1Free Portuguese translation provided by TopCasinoWagering Russion translation provided by Igor Spanish translation provided by itthinx and Ibidem Translations Many thanks!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C