Comments – wpDiscuz

Explore Comments – wpDiscuz vulnerabilities across all versions. Currently tracking 25 known vulnerabilities, including severity, impact, and patch status.

01234567891030.11.2014Today30.05.20166.1Comments - wpDiscuz <= 3.1.4 - Reflected Cross-Site Scripting CVSS 6.1 · 30.05.201612.06.20209.8Comments - wpDiscuz <= 5.3.5 - Blind SQL Injection via order Parameter CVSS 9.8 · 12.06.202006.06.20219.8Comments - wpDiscuz 7.0 - 7.0.4 - Unauthenticated Arbitrary File Upload leading to Remote Code Execution CVSS 9.8 · 06.06.202113.09.20214.8Comments - wpDiscuz <= 7.3.0 - Authenticated Stored Cross-Site Scripting CVSS 4.8 · 13.09.202111.10.20214.3Comments - wpDiscuz <= 7.3.3 - Arbitrary Comment Addition/Edition/Deletion by Cross-Site Request Forgery CVSS 4.3 · 11.10.202110.02.20223.7Comments - wpDiscuz <= 7.3.11 Sensitive Information Disclosure CVSS 3.7 · 10.02.202228.10.20225.4Comments – wpDiscuz <= 7.4.2 - Insecure Direct Object References CVSS 5.4 · 28.10.202212.09.20235.3wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Post Rating Increase/Decrease CVSS 5.3 · 12.09.20235.3wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Comment Rating Increase/Decrease CVSS 5.3 · 12.09.202318.09.20238.8wpDiscuz <= 7.6.5 - Unauthenticated SQL Injection CVSS 8.8 · 18.09.202312.10.20235.4wpDiscuz <= 7.6.3 - Missing Authorization via AJAX actions CVSS 5.4 · 12.10.202320.10.20235.3wpDiscuz <= 7.6.10 - Insufficient Authorization to Comment Submission on Deleted Posts CVSS 5.3 · 20.10.202322.10.20234.3wpDiscuz <= 7.6.10 - Unauthenticated Content Injection CVSS 4.3 · 22.10.20232.7wpDiscuz <= 7.6.3 - Authenticated(Author+) Insecure Direct Object Reference CVSS 2.7 · 22.10.202331.10.20237.2wpDiscuz <= 7.6.11 - Unauthenticated Stored Cross-Site Scripting via Comment Uploaded Image Filename CVSS 7.2 · 31.10.202314.11.20234.3wpDiscuz <= 7.6.11 - Cross-Site Request Forgery CVSS 4.3 · 14.11.202317.11.20234.4wpDiscuz <= 7.6.12 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 17.11.202322.04.20246.4wpDiscuz <= 7.6.15 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Alternative Text CVSS 6.4 · 22.04.202406.06.20246.4Comments – wpDiscuz <= 7.6.18 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 06.06.202401.08.20245.3Comments – wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection CVSS 5.3 · 01.08.202424.10.20249.8Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider CVSS 9.8 · 24.10.202422.09.20254.3wpDiscuz <= 7.6.33 - Missing Authorization CVSS 4.3 · 22.09.202511.12.20258.1Comments – wpDiscuz <= 7.6.39 - Unauthenticated Authentication Bypass Through Account Takeover CVSS 8.1 · 11.12.202525.12.20255.3wpDiscuz <= 7.6.42 - Unauthenticated Insecure Direct Object Reference CVSS 5.3 · 25.12.202502.07.20267.2Comments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website' Field CVSS 7.2 · 02.07.2026

Strategic Overview

Avg CVSSMedium
6.0/ 10
Patch Coverage100%
Open

0

Fixed

25

Get automatic notifications for all Comments – wpDiscuz vulnerabilities before they are exploited.

Vulnerability Records

25 records
2026-07-02 17:39CVE-2026-9148
7.2
High
mickeyjoeYes
2025-12-25 00:00CVE-2025-68997
5.3
Medium
Doan Dinh Van (d52v)Yes
2025-12-11 00:00CVE-2025-13820
8.1
High
wesley (wcraft)Yes
2025-09-22 00:00CVE-2025-59591
4.3
Medium
Legion HunterYes
2024-10-24 00:00CVE-2024-9488
9.8
Critical
wesley (wcraft)Yes
2024-08-01 00:00CVE-2024-6704
5.3
Medium
Tieu Pham Trong NhanYes
2024-06-06 00:00CVE-2024-35681
6.4
Medium
LVT-tholv2kYes
2024-04-22 00:00CVE-2024-2477
6.4
Medium
Ngô Thiên An (ancorn_)Yes
2023-11-17 00:00CVE-2023-51691
4.4
Medium
Jeongwoo-Lee(Roronoa)Yes
2023-11-14 00:00CVE-2023-47775
4.3
Medium
R3N0Yes
Showing 1–10 of 25 reports
Comments &#8211; wpDiscuz banner
Latestv7.6.61

Comments &#8211; wpDiscuz

AdvancedCoding

Author

AdvancedCoding

4.7(578)
94/100
Last Updated
2026-07-27 (3d ago)
Active Installs
70,000+
Downloads
4,682,348
Requires WP
6.0+
Requires PHP
7.4+
Tested up to
WP 7.0.2
Created
2014-11-30 (12y ago)

wpDiscuz is an advanced AJAX-powered WordPress comments plugin that upgrades the default WordPress comment system with live commenting, comment voting, inline feedback, social login, custom comment forms, and modern engagement-focused features. Perfect as a modern Disqus alternative while keeping all comments stored securely in your own WordPress database. Designed to supercharge WordPress native comments, wpDiscuz delivers a fast, lightweight, and highly interactive commenting experience for blogs, news websites, magazines, communities, membership sites, and WooCommerce stores. wpDiscuz version 7 introduces a revolutionary approach to WordPress commenting with innovative engagement tools, optimized AJAX performance, lazy-loaded comments, and a modern responsive design. wpDiscuz Demo: https://wpdiscuz.com/ Support Forum: https://wpdiscuz.com/community/ wpDiscuz GDPR: https://wpdiscuz.com/gdpr/ wpDiscuz Addons: https://wpdiscuz.com/addons/ wpDiscuz Documentation: https://wpdiscuz.com/docs/ wpDiscuz Addons Bundle: https://gvectors.com/product/wpdiscuz-addons-bundle/ Live AJAX Comments Enable fast AJAX-powered live comments for WordPress with instant comment posting, smooth interactions, and real-time updates without page reloads. Inline Commenting and Feedback Allow users to comment directly on post content and provide inline feedback for better discussions and higher user engagement. Comment Voting and Rating Boost community interaction with upvote/downvote comment voting, comment rating, and post rating features. Social Login and Social Comments Allow users to comment using popular social login providers like Facebook and Twitter for a faster commenting experience. Custom WordPress Comment Forms Create custom comment forms and fields for different post types, products, pages, communities, and discussions. WooCommerce Comment Integration Improve WooCommerce product discussions and customer engagement with modern AJAX-powered product comments and rating features. Fast and Lightweight WordPress Comments wpDiscuz is optimized for speed with lazy-loaded comments, built-in caching, AJAX posting, and performance-focused architecture. Disqus Alternative for WordPress Replace Disqus, Jetpack Comments, and other third-party comment systems while keeping full ownership of your comments and user data. Comments – wpDiscuz Features Three modern WordPress comment layouts Fast AJAX-powered WordPress comments Interactive live comment form for WordPress Inline commenting and inline feedback Live notifications with real-time comment bubble updates Social commenting with multiple social login options Post rating and comment rating features Responsive WordPress comment forms and comment threads Modern user interface and user experience Comment sorting by newest, oldest, and most voted comments Anonymous WordPress comments support Integration with social network login plugins Multi-level nested comment threads AJAX “Load More Comments” button Lazy load WordPress comments on scroll WordPress date format integration Comment editing for logged-in users and guests Automatic URL and image embedding in comments Long comment collapsing with “Read More” button Comment subscription and notification options AJAX comment form validation and posting Fully integrated with WordPress native comments Secure anti-spam WordPress comment system Positive and negative comment voting Smart voting system with cookies and user tracking Quick Tags support for comments Custom WordPress comment forms and custom fields Highlighting new comments since last visit Notifications when comments are approved View replies button for nested comments Comment access control by user roles Option to load all comments on first page load Built-in Gravatar caching Sticky comments support Closed comment threads support User follow and subscriptions Built-in comment and author caching system Add-ons | wpDiscuz – Bundle | wpDiscuz – Reviews | wpDiscuz – Emoticons | wpDiscuz – User Notifications | wpDiscuz – Media Uploader | wpDiscuz – Embeds | wpDiscuz – Comment Author Info | wpDiscuz – Google ReCaptcha | wpDiscuz – myCRED Integration | wpDiscuz – Widgets | wpDiscuz – Front-end Moderation | wpDiscuz – Subscription Manager | wpDiscuz – Comment Search | wpDiscuz – Comment Report and Flagging | wpDiscuz – Ads Manager | wpDiscuz – User & Comment Mentioning | wpDiscuz – Advanced Likers | wpDiscuz – Online Users | wpDiscuz – Private Comments | wpDiscuz – Syntax Highlighter | Comments Censure PRO Integration Add-ons | wpDiscuz – BuddyPress Integration | wpDiscuz – GIPHY Integration | wpDiscuz – Voice Commenting

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C