HomeWordPress vulnerabilitiesComments
Comments vulnerabilities
Comments has 16 known vulnerabilities in this database. The most recent published record is dated 2 Sep 2026.
- Known vulnerabilities
- 16
- Active installs
- 60,000+
- Latest version
- 7.6.71
- Last updated
- 16 Sep 2026
- Most recent
- 2 Sep 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| SQL injection CVE-2026-19704 | Medium 5.3 | Before 7.6.66 | Fixed in 7.6.66 | 2 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-15032 | Medium 6.1 | Before 7.6.60 | Fixed in 7.6.60 | 7 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-9148 | High 7.2 | Up to 7.6.56 | Fixed in a later version (latest 7.6.71) | 3 Jul 2026 |
| Cross-site scripting (XSS) CVE-2026-22210 | Medium 4.4 | Before 7.6.47 | Fixed in 7.6.47 | 13 Mar 2026 |
| Security weakness CVE-2025-13820 | Medium 5.3 | Before 7.6.40 | Fixed in 7.6.40 | 1 Jan 2026 |
| Authentication bypass CVE-2024-9488 | Critical 9.8 | Before 7.6.25 | Fixed in 7.6.25 | 25 Oct 2024 |
| Content injection CVE-2024-6704 | Medium 5.3 | Before 7.6.22 | Fixed in 7.6.22 | 2 Aug 2024 |
| Cross-site scripting (XSS) CVE-2024-2477 | Medium 6.4 | Before 7.6.16 | Fixed in 7.6.16 | 23 Apr 2024 |
| Broken access control CVE-2023-3869 | Medium 5.3 | Up to 7.6.3 | Fixed in a later version (latest 7.6.71) | 20 Oct 2023 |
| Broken access control CVE-2023-3998 | Medium 5.3 | Up to 7.6.3 | Fixed in a later version (latest 7.6.71) | 20 Oct 2023 |
| Broken access control CVE-2022-43492 | Medium 4.3 | Not yet published | Check for an update | 18 Nov 2022 |
| Sensitive data exposure CVE-2022-23984 | Low 3.7 | Up to 7.3.11 | Fixed in a later version (latest 7.6.71) | 21 Feb 2022 |
| Cross-site request forgery (CSRF) CVE-2021-24806 | Medium 4.3 | Before 7.3.4 | Fixed in 7.3.4 | 8 Nov 2021 |
| Cross-site scripting (XSS) CVE-2021-24737 | Medium 4.8 | Up to 7.3.0 | Fixed in a later version (latest 7.6.71) | 11 Oct 2021 |
| Remote code execution CVE-2020-24186 | Critical 10.0 | Up to 7.0.4 | Fixed in a later version (latest 7.6.71) | 24 Aug 2020 |
| SQL injection CVE-2020-13640 | Critical 9.8 | Up to 5.3.5 | Fixed in a later version (latest 7.6.71) | 18 Jun 2020 |
Read the published descriptions
- CVE-2026-19704, 2 Sep 2026
- The Comments WordPress plugin before 7.6.66 does not validate a value used to build a database query, allowing unauthenticated users to inject SQL and read comments they are not entitled to see, including comments awaiting moderation, comments marked as spam or trashed, and comments on private and draft posts. The injected text reaches the query as grammar rather than as data and does not yield extraction of arbitrary data, so the confidentiality impact is the disclosed comment content rather than the database at large. CVE record
- CVE-2026-15032, 7 Aug 2026
- The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store a Cross-Site Scripting payload that executes in the browser of any user, including administrators, who views the affected content. CVE record
- CVE-2026-9148, 3 Jul 2026
- The Comments - wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAuthor() function, which interpolates the stored comment_author_url value directly into single-quoted HTML attributes without applying esc_url() or esc_attr(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-22210, 13 Mar 2026
- wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through unescaped attachment URLs in HTML output by exploiting the WpdiscuzHelperUpload class. Attackers can craft malicious attachment records or filter hooks to inject arbitrary JavaScript into img and anchor tag attributes, executing code in the context of WordPress users viewing comments. CVE record
- CVE-2025-13820, 1 Jan 2026
- The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet. CVE record
- CVE-2024-9488, 25 Oct 2024
- The Comments - wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token. CVE record
- CVE-2024-6704, 2 Aug 2024
- The Comments - wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of filtering of HTML tags in comments. This makes it possible for unauthenticated attackers to add HTML such as hyperlinks to comments when rich editing is disabled. CVE record
- CVE-2024-2477, 23 Apr 2024
- The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of an uploaded image in all versions up to, and including, 7.6.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2023-3869, 20 Oct 2023
- The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a comment. CVE record
- CVE-2023-3998, 20 Oct 2023
- The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a post. CVE record
- CVE-2022-43492, 18 Nov 2022
- Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments - wpDiscuz plugin 7.4.2 on WordPress. CVE record
- CVE-2022-23984, 21 Feb 2022
- Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11). CVE record
- CVE-2021-24806, 8 Nov 2021
- The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment. CVE record
- CVE-2021-24737, 11 Oct 2021
- The Comments - wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. CVE record
- CVE-2020-24186, 24 Aug 2020
- A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action. CVE record
- CVE-2020-13640, 18 Jun 2020
- A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.) CVE record
What to do if you run Comments
If you run Comments, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Comments vulnerabilities
Free. We email you when a new vulnerability is published for Comments, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.