Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesComments

Comments vulnerabilities

Comments has 16 known vulnerabilities in this database. The most recent published record is dated 2 Sep 2026.

Known vulnerabilities
16
Active installs
60,000+
Latest version
7.6.71
Last updated
16 Sep 2026
Most recent
2 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
SQL injection
CVE-2026-19704
Medium 5.3Before 7.6.66Fixed in 7.6.662 Sep 2026
Cross-site scripting (XSS)
CVE-2026-15032
Medium 6.1Before 7.6.60Fixed in 7.6.607 Aug 2026
Cross-site scripting (XSS)
CVE-2026-9148
High 7.2Up to 7.6.56Fixed in a later version (latest 7.6.71)3 Jul 2026
Cross-site scripting (XSS)
CVE-2026-22210
Medium 4.4Before 7.6.47Fixed in 7.6.4713 Mar 2026
Security weakness
CVE-2025-13820
Medium 5.3Before 7.6.40Fixed in 7.6.401 Jan 2026
Authentication bypass
CVE-2024-9488
Critical 9.8Before 7.6.25Fixed in 7.6.2525 Oct 2024
Content injection
CVE-2024-6704
Medium 5.3Before 7.6.22Fixed in 7.6.222 Aug 2024
Cross-site scripting (XSS)
CVE-2024-2477
Medium 6.4Before 7.6.16Fixed in 7.6.1623 Apr 2024
Broken access control
CVE-2023-3869
Medium 5.3Up to 7.6.3Fixed in a later version (latest 7.6.71)20 Oct 2023
Broken access control
CVE-2023-3998
Medium 5.3Up to 7.6.3Fixed in a later version (latest 7.6.71)20 Oct 2023
Broken access control
CVE-2022-43492
Medium 4.3Not yet publishedCheck for an update18 Nov 2022
Sensitive data exposure
CVE-2022-23984
Low 3.7Up to 7.3.11Fixed in a later version (latest 7.6.71)21 Feb 2022
Cross-site request forgery (CSRF)
CVE-2021-24806
Medium 4.3Before 7.3.4Fixed in 7.3.48 Nov 2021
Cross-site scripting (XSS)
CVE-2021-24737
Medium 4.8Up to 7.3.0Fixed in a later version (latest 7.6.71)11 Oct 2021
Remote code execution
CVE-2020-24186
Critical 10.0Up to 7.0.4Fixed in a later version (latest 7.6.71)24 Aug 2020
SQL injection
CVE-2020-13640
Critical 9.8Up to 5.3.5Fixed in a later version (latest 7.6.71)18 Jun 2020
Read the published descriptions
CVE-2026-19704, 2 Sep 2026
The Comments WordPress plugin before 7.6.66 does not validate a value used to build a database query, allowing unauthenticated users to inject SQL and read comments they are not entitled to see, including comments awaiting moderation, comments marked as spam or trashed, and comments on private and draft posts. The injected text reaches the query as grammar rather than as data and does not yield extraction of arbitrary data, so the confidentiality impact is the disclosed comment content rather than the database at large. CVE record
CVE-2026-15032, 7 Aug 2026
The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unauthenticated users to store a Cross-Site Scripting payload that executes in the browser of any user, including administrators, who views the affected content. CVE record
CVE-2026-9148, 3 Jul 2026
The Comments - wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAuthor() function, which interpolates the stored comment_author_url value directly into single-quoted HTML attributes without applying esc_url() or esc_attr(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-22210, 13 Mar 2026
wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through unescaped attachment URLs in HTML output by exploiting the WpdiscuzHelperUpload class. Attackers can craft malicious attachment records or filter hooks to inject arbitrary JavaScript into img and anchor tag attributes, executing code in the context of WordPress users viewing comments. CVE record
CVE-2025-13820, 1 Jan 2026
The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet. CVE record
CVE-2024-9488, 25 Oct 2024
The Comments - wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token. CVE record
CVE-2024-6704, 2 Aug 2024
The Comments - wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of filtering of HTML tags in comments. This makes it possible for unauthenticated attackers to add HTML such as hyperlinks to comments when rich editing is disabled. CVE record
CVE-2024-2477, 23 Apr 2024
The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of an uploaded image in all versions up to, and including, 7.6.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2023-3869, 20 Oct 2023
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the voteOnComment function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a comment. CVE record
CVE-2023-3998, 20 Oct 2023
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a post. CVE record
CVE-2022-43492, 18 Nov 2022
Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments - wpDiscuz plugin 7.4.2 on WordPress. CVE record
CVE-2022-23984, 21 Feb 2022
Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11). CVE record
CVE-2021-24806, 8 Nov 2021
The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could allow attacker to make logged in users such as admin edit and delete arbitrary comment, or the user who made the comment to edit it via a CSRF attack. Attackers could also make logged in users post arbitrary comment. CVE record
CVE-2021-24737, 11 Oct 2021
The Comments - wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow messages before outputting them in the page, which could allow high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. CVE record
CVE-2020-24186, 24 Aug 2020
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action. CVE record
CVE-2020-13640, 18 Jun 2020
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.) CVE record

What to do if you run Comments

If you run Comments, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Comments vulnerabilities

Free. We email you when a new vulnerability is published for Comments, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support