Comments – wpDiscuz

Comments – wpDiscuz has 27 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2026; all 27 are fixed as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 9.8 out of 10. Severity breakdown: 3 critical and 5 high. 2023 was the busiest year with 10 disclosures.

The most common weakness is Cross-Site Scripting, behind 9 of the records (33%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Missing Authorization.

Every one of the 27 issues recorded for Comments – wpDiscuz has a vendor fix available, so running the current release closes all known holes.

19 independent researchers contributed these findings, most of them (5) reported by R3N0. Comments – wpDiscuz is installed on roughly 60,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891030.11.2014Today30.05.20166.1Comments - wpDiscuz <= 3.1.4 - Reflected Cross-Site Scripting CVSS 6.1 · 30.05.201612.06.20209.8Comments - wpDiscuz <= 5.3.5 - Blind SQL Injection via order Parameter CVSS 9.8 · 12.06.202006.06.20219.8Comments - wpDiscuz 7.0 - 7.0.4 - Unauthenticated Arbitrary File Upload leading to Remote Code Execution CVSS 9.8 · 06.06.202113.09.20214.8Comments - wpDiscuz <= 7.3.0 - Authenticated Stored Cross-Site Scripting CVSS 4.8 · 13.09.202111.10.20214.3Comments - wpDiscuz <= 7.3.3 - Arbitrary Comment Addition/Edition/Deletion by Cross-Site Request Forgery CVSS 4.3 · 11.10.202110.02.20223.7Comments - wpDiscuz <= 7.3.11 Sensitive Information Disclosure CVSS 3.7 · 10.02.202228.10.20225.4Comments – wpDiscuz <= 7.4.2 - Insecure Direct Object References CVSS 5.4 · 28.10.202212.09.20235.3wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Post Rating Increase/Decrease CVSS 5.3 · 12.09.20235.3wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Comment Rating Increase/Decrease CVSS 5.3 · 12.09.202318.09.20238.8wpDiscuz <= 7.6.5 - Unauthenticated SQL Injection CVSS 8.8 · 18.09.202312.10.20235.4wpDiscuz <= 7.6.3 - Missing Authorization via AJAX actions CVSS 5.4 · 12.10.202320.10.20235.3wpDiscuz <= 7.6.10 - Insufficient Authorization to Comment Submission on Deleted Posts CVSS 5.3 · 20.10.202322.10.20234.3wpDiscuz <= 7.6.10 - Unauthenticated Content Injection CVSS 4.3 · 22.10.20232.7wpDiscuz <= 7.6.3 - Authenticated(Author+) Insecure Direct Object Reference CVSS 2.7 · 22.10.202331.10.20237.2wpDiscuz <= 7.6.11 - Unauthenticated Stored Cross-Site Scripting via Comment Uploaded Image Filename CVSS 7.2 · 31.10.202314.11.20234.3wpDiscuz <= 7.6.11 - Cross-Site Request Forgery CVSS 4.3 · 14.11.202317.11.20234.4wpDiscuz <= 7.6.12 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 17.11.202322.04.20246.4wpDiscuz <= 7.6.15 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Alternative Text CVSS 6.4 · 22.04.202406.06.20246.4Comments – wpDiscuz <= 7.6.18 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 06.06.202401.08.20245.3Comments – wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection CVSS 5.3 · 01.08.202424.10.20249.8Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider CVSS 9.8 · 24.10.202422.09.20254.3wpDiscuz <= 7.6.33 - Missing Authorization CVSS 4.3 · 22.09.202511.12.20258.1Comments – wpDiscuz <= 7.6.39 - Unauthenticated Authentication Bypass Through Account Takeover CVSS 8.1 · 11.12.202525.12.20255.3wpDiscuz <= 7.6.42 - Unauthenticated Insecure Direct Object Reference CVSS 5.3 · 25.12.202512.03.20264.4Comments – wpDiscuz <= 7.6.46 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 12.03.202602.07.20267.2Comments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website' Field CVSS 7.2 · 02.07.202602.09.20267.5Comments – wpDiscuz < 7.6.66 - Unauthenticated SQL Injection CVSS 7.5 · 02.09.2026

Strategic Overview

Avg CVSSMedium
6.0/ 10
Patch Coverage100%
Open

0

Fixed

27

Get automatic notifications for all Comments – wpDiscuz vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2024-9488

Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider

Read the full analysis

Vulnerability Records

27 records
2026-09-02 00:00CVE-2026-19704
7.5
High
Jakub HermanYes
2026-07-02 17:39CVE-2026-9148
7.2
High
mickeyjoeYes
2026-03-12 00:00CVE-2026-22209
4.4
Medium
Scott Moore - VulnCheckYes
2025-12-25 00:00CVE-2025-68997
5.3
Medium
Doan Dinh Van (d52v)Yes
2025-12-11 00:00CVE-2025-13820
8.1
High
wesley (wcraft)Yes
2025-09-22 00:00CVE-2025-59591
4.3
Medium
Legion HunterYes
2024-10-24 00:00CVE-2024-9488
9.8
Critical
wesley (wcraft)Yes
2024-08-01 00:00CVE-2024-6704
5.3
Medium
Tieu Pham Trong NhanYes
2024-06-06 00:00CVE-2024-35681
6.4
Medium
LVT-tholv2kYes
2024-04-22 00:00CVE-2024-2477
6.4
Medium
Ngô Thiên An (ancorn_)Yes
Showing 1–10 of 27 reports
Comments – wpDiscuz banner
Latestv7.6.70

Comments – wpDiscuz

AdvancedCoding

Author

AdvancedCoding

4.7(579)
94/100
Last Updated
2026-09-11 (1d ago)
Active Installs
60,000+
Downloads
4,874,422
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2014-11-30 (12y ago)

wpDiscuz transforms the native WordPress comment system into a fast, modern, and interactive discussion experience while keeping your comments and data in your own WordPress database. Add AJAX comments, live comments, threaded comments, comment voting and rating, inline comments, comment subscriptions, social login, custom comment forms, lazy loading, and modern engagement features without moving your community to an external commenting service. wpDiscuz is a powerful Disqus alternative for WordPress and is designed for blogs, news websites, magazines, communities, membership sites, and WooCommerce stores. wpDiscuz Demo: https://wpdiscuz.com/ Documentation: https://wpdiscuz.com/docs/ Support Forum: https://wpdiscuz.com/community/ GDPR Information: https://wpdiscuz.com/gdpr/ wpDiscuz Add-ons: https://wpdiscuz.com/addons/ AJAX Comments Enable fast AJAX-powered WordPress comments with instant comment posting, smooth interactions, and updates without unnecessary page reloads. Live Comments Create a more dynamic discussion experience with live comment updates, live notifications, and real-time comment bubble updates. Threaded Comments and Replies Organize discussions with multi-level threaded comments, nested replies, and reply controls that make long conversations easier to follow. Comment Voting and Rating Increase community interaction with positive and negative comment voting, comment rating, and post rating features. Inline Comments and Feedback Let visitors comment directly on post content and provide inline feedback without relying only on the main comment form. Comment Subscriptions and Notifications Allow users to subscribe to comments and discussion updates and receive notifications about new activity, replies, and approved comments. Custom WordPress Comment Forms Create custom comment forms and custom fields for different post types, products, pages, communities, and discussions. Social Login and Social Comments Allow visitors to comment using supported social login providers for a faster and more convenient commenting experience. WooCommerce Comments and Reviews Improve WooCommerce product discussions with AJAX-powered product comments, ratings, and engagement features. Advanced WooCommerce review and rating functionality is available with the wpDiscuz – Reviews add-on. Performance and Lazy Loading wpDiscuz is optimized for performance with lazy-loaded comments, built-in caching, AJAX posting, Gravatar caching, and a performance-focused architecture. Disqus Alternative for WordPress Replace Disqus, Jetpack Comments, and other third-party comment systems while keeping full ownership of your comments and storing them in the native WordPress comment database. More wpDiscuz Features Three modern WordPress comment layouts Comment sorting by newest, oldest, and most voted comments Comment editing for logged-in users and guests Automatic URL and image embedding in comments Long comment collapsing with “Read More” button WordPress date format integration Quick Tags support for comments Highlighting new comments since last visit Comment access control by user roles Option to load all comments on first page load Built-in Gravatar caching Sticky comments support Closed comment threads support User follow functionality Built-in comment and author caching system Responsive interface for desktop and mobile devices wpDiscuz Add-ons Extend wpDiscuz with optional add-ons for advanced reviews and ratings, media uploads, user notifications, front-end moderation, subscriptions, comment search, private comments, BuddyPress integration, GIPHY integration, voice commenting, and more. Browse wpDiscuz Add-ons wpDiscuz Add-ons Bundle

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C