Wpdiscuz
Gvectors · 33 CVEs
wpDiscuz before 7.6.47 - No Rate Limiting on Subscription Endpoints with LIKE Wildcard Bypass
Mar 13, 2026
wpDiscuz before 7.6.47 - Missing CSRF Protection on wpdGetFollowsPage
Mar 13, 2026
wpDiscuz before 7.6.47 - Cross-Site Scripting via Unescaped Attachment URLs
Mar 13, 2026
wpDiscuz before 7.6.47 - Cross-Site Scripting via Unescaped Custom CSS in Style Tag
Mar 13, 2026
wpDiscuz before 7.6.47 - Unsanitized Cookie Email Used as wp_mail() Recipient
Mar 13, 2026
wpDiscuz before 7.6.47 - Options Export Leaks OAuth Secrets in Plaintext
Mar 13, 2026
wpDiscuz before 7.6.47 - Destructive GET Action Deletes All Comments by Email
Mar 13, 2026
wpDiscuz before 7.6.47 - IP Address Spoofing in getIP()
Mar 13, 2026
Voltronic Power SNMP Web Pro 1.1 Path Traversal via upload.cgi
Mar 13, 2026
wpDiscuz before 7.6.47 - SQL Injection in getAllSubscriptions()
Mar 13, 2026
Voltronic Power SNMP Web Pro 1.1 Authentication Bypass via localStorage
Mar 13, 2026
Beghelli Sicuro24 SicuroWeb AngularJS Template Injection
Mar 13, 2026
wpDiscuz before 7.6.47 - Stored Cross-Site Scripting in Inline Comment Preview
Mar 13, 2026
wpDiscuz before 7.6.47 - Unauthenticated Email Notification Flood via wpdCheckNotificationType
Mar 13, 2026
WordPress wpDiscuz plugin <= 7.6.10 - Broken Access Control vulnerability
Jan 2, 2025
WordPress wpDiscuz plugin <= 7.6.3 - Broken Access Control vulnerability
Jan 2, 2025
Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider
Oct 25, 2024
Comments – wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection
Aug 2, 2024
WordPress wpDiscuz plugin <= 7.6.18 - Cross Site Scripting (XSS) vulnerability
Jun 8, 2024
WordPress wpDiscuz plugin <= 7.6.10 - Content Injection vulnerability
Jun 4, 2024
wpDiscuz <= 7.6.15 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Alternative Text
Apr 23, 2024
WordPress wpDiscuz Plugin <= 7.6.12 is vulnerable to Cross Site Scripting (XSS)
Feb 1, 2024
WordPress wpDiscuz Plugin <= 7.6.3 is vulnerable to Insecure Direct Object References (IDOR)
Dec 20, 2023
WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Request Forgery (CSRF)
Nov 22, 2023
WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Scripting (XSS)
Nov 6, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-22216 | wpDiscuz before 7.6.47 - No Rate Limiting on Subscription Endpoints with LIKE Wildcard Bypass | MEDIUM | 0.32% | Mar 13, 2026 |
| CVE-2026-22215 | wpDiscuz before 7.6.47 - Missing CSRF Protection on wpdGetFollowsPage | MEDIUM | 0.15% | Mar 13, 2026 |
| CVE-2026-22210 | wpDiscuz before 7.6.47 - Cross-Site Scripting via Unescaped Attachment URLs | LOW | 0.16% | Mar 13, 2026 |
| CVE-2026-22209 | wpDiscuz before 7.6.47 - Cross-Site Scripting via Unescaped Custom CSS in Style Tag | MEDIUM | 0.22% | Mar 13, 2026 |
| CVE-2026-22204 | wpDiscuz before 7.6.47 - Unsanitized Cookie Email Used as wp_mail() Recipient | MEDIUM | 0.22% | Mar 13, 2026 |
| CVE-2026-22203 | wpDiscuz before 7.6.47 - Options Export Leaks OAuth Secrets in Plaintext | MEDIUM | 0.27% | Mar 13, 2026 |
| CVE-2026-22202 | wpDiscuz before 7.6.47 - Destructive GET Action Deletes All Comments by Email | MEDIUM | 0.17% | Mar 13, 2026 |
| CVE-2026-22201 | wpDiscuz before 7.6.47 - IP Address Spoofing in getIP() | MEDIUM | 0.15% | Mar 13, 2026 |
| CVE-2026-22199 | Voltronic Power SNMP Web Pro 1.1 Path Traversal via upload.cgi | HIGH | 0.98% | Mar 13, 2026 |
| CVE-2026-22193 | wpDiscuz before 7.6.47 - SQL Injection in getAllSubscriptions() | CRITICAL | 0.30% | Mar 13, 2026 |
| CVE-2026-22192 | Voltronic Power SNMP Web Pro 1.1 Authentication Bypass via localStorage | HIGH | 0.27% | Mar 13, 2026 |
| CVE-2026-22191 | Beghelli Sicuro24 SicuroWeb AngularJS Template Injection | MEDIUM | 0.36% | Mar 13, 2026 |
| CVE-2026-22183 | wpDiscuz before 7.6.47 - Stored Cross-Site Scripting in Inline Comment Preview | MEDIUM | 0.17% | Mar 13, 2026 |
| CVE-2026-22182 | wpDiscuz before 7.6.47 - Unauthenticated Email Notification Flood via wpdCheckNotificationType | HIGH | 0.52% | Mar 13, 2026 |
| CVE-2023-46309 | WordPress wpDiscuz plugin <= 7.6.10 - Broken Access Control vulnerability | HIGH | 0.35% | Jan 2, 2025 |
| CVE-2023-45760 | WordPress wpDiscuz plugin <= 7.6.3 - Broken Access Control vulnerability | HIGH | 0.41% | Jan 2, 2025 |
| CVE-2024-9488 | Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider | CRITICAL | 0.81% | Oct 25, 2024 |
| CVE-2024-6704 | Comments – wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection | MEDIUM | 0.60% | Aug 2, 2024 |
| CVE-2024-35681 | WordPress wpDiscuz plugin <= 7.6.18 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 0.26% | Jun 8, 2024 |
| CVE-2023-46310 | WordPress wpDiscuz plugin <= 7.6.10 - Content Injection vulnerability | MEDIUM | 0.28% | Jun 4, 2024 |
| CVE-2024-2477 | wpDiscuz <= 7.6.15 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Alternative Text | MEDIUM | 0.34% | Apr 23, 2024 |
| CVE-2023-51691 | WordPress wpDiscuz Plugin <= 7.6.12 is vulnerable to Cross Site Scripting (XSS) | MEDIUM | 0.34% | Feb 1, 2024 |
| CVE-2023-46311 | WordPress wpDiscuz Plugin <= 7.6.3 is vulnerable to Insecure Direct Object References (IDOR) | MEDIUM | 0.52% | Dec 20, 2023 |
| CVE-2023-47775 | WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Request Forgery (CSRF) | HIGH | 0.26% | Nov 22, 2023 |
| CVE-2023-47185 | WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Scripting (XSS) | HIGH | 0.37% | Nov 6, 2023 |
Showing 1 to 25 of 33 CVEs