Wpdiscuz

Gvectors · 33 CVEs

CVE-2026-22216
MEDIUM

wpDiscuz before 7.6.47 - No Rate Limiting on Subscription Endpoints with LIKE Wildcard Bypass

Mar 13, 2026

CVE-2026-22215
MEDIUM

wpDiscuz before 7.6.47 - Missing CSRF Protection on wpdGetFollowsPage

Mar 13, 2026

CVE-2026-22210
LOW

wpDiscuz before 7.6.47 - Cross-Site Scripting via Unescaped Attachment URLs

Mar 13, 2026

CVE-2026-22209
MEDIUM

wpDiscuz before 7.6.47 - Cross-Site Scripting via Unescaped Custom CSS in Style Tag

Mar 13, 2026

CVE-2026-22204
MEDIUM

wpDiscuz before 7.6.47 - Unsanitized Cookie Email Used as wp_mail() Recipient

Mar 13, 2026

CVE-2026-22203
MEDIUM

wpDiscuz before 7.6.47 - Options Export Leaks OAuth Secrets in Plaintext

Mar 13, 2026

CVE-2026-22202
MEDIUM

wpDiscuz before 7.6.47 - Destructive GET Action Deletes All Comments by Email

Mar 13, 2026

CVE-2026-22201
MEDIUM

wpDiscuz before 7.6.47 - IP Address Spoofing in getIP()

Mar 13, 2026

CVE-2026-22199
HIGH

Voltronic Power SNMP Web Pro 1.1 Path Traversal via upload.cgi

Mar 13, 2026

CVE-2026-22193
CRITICAL

wpDiscuz before 7.6.47 - SQL Injection in getAllSubscriptions()

Mar 13, 2026

CVE-2026-22192
HIGH

Voltronic Power SNMP Web Pro 1.1 Authentication Bypass via localStorage

Mar 13, 2026

CVE-2026-22191
MEDIUM

Beghelli Sicuro24 SicuroWeb AngularJS Template Injection

Mar 13, 2026

CVE-2026-22183
MEDIUM

wpDiscuz before 7.6.47 - Stored Cross-Site Scripting in Inline Comment Preview

Mar 13, 2026

CVE-2026-22182
HIGH

wpDiscuz before 7.6.47 - Unauthenticated Email Notification Flood via wpdCheckNotificationType

Mar 13, 2026

CVE-2023-46309
HIGH

WordPress wpDiscuz plugin <= 7.6.10 - Broken Access Control vulnerability

Jan 2, 2025

CVE-2023-45760
HIGH

WordPress wpDiscuz plugin <= 7.6.3 - Broken Access Control vulnerability

Jan 2, 2025

CVE-2024-9488
CRITICAL

Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider

Oct 25, 2024

CVE-2024-6704
MEDIUM

Comments – wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection

Aug 2, 2024

CVE-2024-35681
MEDIUM

WordPress wpDiscuz plugin <= 7.6.18 - Cross Site Scripting (XSS) vulnerability

Jun 8, 2024

CVE-2023-46310
MEDIUM

WordPress wpDiscuz plugin <= 7.6.10 - Content Injection vulnerability

Jun 4, 2024

CVE-2024-2477
MEDIUM

wpDiscuz <= 7.6.15 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Alternative Text

Apr 23, 2024

CVE-2023-51691
MEDIUM

WordPress wpDiscuz Plugin <= 7.6.12 is vulnerable to Cross Site Scripting (XSS)

Feb 1, 2024

CVE-2023-46311
MEDIUM

WordPress wpDiscuz Plugin <= 7.6.3 is vulnerable to Insecure Direct Object References (IDOR)

Dec 20, 2023

CVE-2023-47775
HIGH

WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Request Forgery (CSRF)

Nov 22, 2023

CVE-2023-47185
HIGH

WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Scripting (XSS)

Nov 6, 2023

Showing 1 to 25 of 33 CVEs