Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wpDiscuz — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in wpDiscuz, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of security vulnerabilities, weaknesses, and advisories specifically related to the wpDiscuz WordPress plugin, categorized by vulnerability type and severity tags. It collects a wide range of security issues affecting this popular commenting system, including SQL injection, cross-site scripting, and privilege escalation flaws, covering data from initial releases through recent updates to ensure a complete historical perspective. By reviewing this consolidated information, researchers and administrators can effectively track vendor advisories to stay informed about patches, gain a deeper understanding of specific weakness classes and their exploit mechanisms within the wpDiscuz ecosystem, and look up the product’s comprehensive vulnerability history to assess long-term security trends and risks. The data is structured to facilitate quick identification of affected versions and associated remediation steps, allowing users to prioritize critical fixes based on the severity and likelihood of exploitation. This resource serves as a centralized reference point for security professionals evaluating the risk posture of sites utilizing wpDiscuz, enabling them to make informed decisions about updating configurations or applying patches. It does not cover third-party dependencies or unrelated WordPress core issues, focusing strictly on flaws originating from or impacting the wpDiscuz plugin itself. The content is regularly updated to reflect the latest disclosures and mitigation strategies, ensuring that the information remains accurate and actionable for maintaining a secure environment.

Vendor: gVectors Team

CVE IDTitleCVSSSeverityPublished
CVE-2026-22216 wpDiscuz before 7.6.47 - No Rate Limiting on Subscription Endpoints with LIKE Wildcard Bypass CWE-799 6.5 Medium2026-03-13
CVE-2026-22215 wpDiscuz before 7.6.47 - Missing CSRF Protection on wpdGetFollowsPage CWE-352 4.3 Medium2026-03-13
CVE-2026-22210 wpDiscuz before 7.6.47 - Cross-Site Scripting via Unescaped Attachment URLs CWE-79 4.4 Medium2026-03-13
CVE-2026-22209 wpDiscuz before 7.6.47 - Cross-Site Scripting via Unescaped Custom CSS in Style Tag CWE-79 5.5 Medium2026-03-13
CVE-2026-22204 wpDiscuz before 7.6.47 - Unsanitized Cookie Email Used as wp_mail() Recipient CWE-20 3.7 Low2026-03-13
CVE-2026-22203 wpDiscuz before 7.6.47 - Options Export Leaks OAuth Secrets in Plaintext CWE-200 4.9 Medium2026-03-13
CVE-2026-22202 wpDiscuz before 7.6.47 - Destructive GET Action Deletes All Comments by Email CWE-352 8.1 High2026-03-13
CVE-2026-22201 wpDiscuz before 7.6.47 - IP Address Spoofing in getIP() CWE-348 5.3 Medium2026-03-13
CVE-2026-22193 wpDiscuz before 7.6.47 - SQL Injection in getAllSubscriptions() CWE-89 8.1 High2026-03-13
CVE-2026-22183 wpDiscuz before 7.6.47 - Stored Cross-Site Scripting in Inline Comment Preview CWE-79 6.1 Medium2026-03-13
CVE-2026-22182 wpDiscuz before 7.6.47 - Unauthenticated Email Notification Flood via wpdCheckNotificationType CWE-862 7.5 High2026-03-13
CVE-2025-68997 WordPress wpDiscuz plugin <= 7.6.43 - Insecure Direct Object References (IDOR) vulnerability CWE-639 5.3 Medium2025-12-30
CVE-2025-59591 WordPress wpDiscuz Plugin <= 7.6.33 - Broken Access Control Vulnerability CWE-862 4.3 Medium2025-09-22
CVE-2023-46309 WordPress wpDiscuz plugin <= 7.6.10 - Broken Access Control vulnerability CWE-862 5.3 Medium2025-01-02
CVE-2023-45760 WordPress wpDiscuz plugin <= 7.6.3 - Broken Access Control vulnerability CWE-862 4.3 Medium2025-01-02
CVE-2024-35681 WordPress wpDiscuz plugin <= 7.6.18 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-06-08
CVE-2023-46310 WordPress wpDiscuz plugin <= 7.6.10 - Content Injection vulnerability CWE-80 5.3 Medium2024-06-04

All 17 known CVE vulnerabilities affecting wpDiscuz with full Chinese analysis, references, and POCs where available.