Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Comments – wpDiscuz Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 26 vulnerability records associated with Comments – wpDiscuz, published between 2016 and 2026.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

26Total records
3Critical
4High
16Medium
2Low
1Informational
26Patched records
0Currently marked unpatched
2016-05-30First disclosure
2026-07-02Latest disclosure
24 of 26CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201611 records
202011 records
202133 records
202222 records
20231010 records
202444 records
202533 records
202622 records

Severity Breakdown

SeverityRecordsShare
Critical311.5%
High415.4%
Medium1661.5%
Low27.7%
Informational13.8%

Vulnerability-Type Breakdown

Cross-Site Scripting

9 records34.6%

First: 2016. Latest: 2026.

Missing Authorization

9 records34.6%

First: 2022. Latest: 2025.

SQL Injection

2 records7.7%

First: 2020. Latest: 2023.

CSRF

2 records7.7%

First: 2021. Latest: 2023.

Arbitrary File Upload

1 record3.8%

First: 2021. Latest: 2021.

Information Disclosure

1 record3.8%

First: 2022. Latest: 2022.

Other

1 record3.8%

First: 2023. Latest: 2023.

Authentication Bypass

1 record3.8%

First: 2024. Latest: 2024.

Patch Status

Patched
26
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 7.6.57
  • 7.6.47
  • 7.6.44
  • 7.6.40
  • 7.6.34
  • 7.6.25
  • 7.6.22
  • 7.6.19
  • 7.6.16
  • 7.6.13
  • 7.6.12
  • 7.6.4
  • 7.6.11
  • 7.6.6
  • 7.5
  • 7.3.12
  • 7.3.4
  • 7.3.2
  • 7.0.5
  • 5.3.6
  • 3.2.0

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-7.6.56Comments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website' FieldJuly 2, 20267.6.57High
*-7.6.46Comments – wpDiscuz <= 7.6.46 - Authenticated (Admin+) Stored Cross-Site ScriptingMarch 12, 20267.6.47Medium
*-7.6.42wpDiscuz <= 7.6.42 - Unauthenticated Insecure Direct Object ReferenceDecember 25, 20257.6.44Medium
*-7.6.39Comments – wpDiscuz <= 7.6.39 - Unauthenticated Authentication Bypass Through Account TakeoverDecember 11, 20257.6.40High
*-7.6.33wpDiscuz <= 7.6.33 - Missing AuthorizationSeptember 22, 20257.6.34Medium
*-7.6.24Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth providerOctober 24, 20247.6.25Critical
*-7.6.21Comments – wpDiscuz <= 7.6.21 - Unauthenticated HTML InjectionAugust 1, 20247.6.22Medium
*-7.6.18Comments – wpDiscuz <= 7.6.18 - Authenticated (Contributor+) Stored Cross-Site ScriptingJune 6, 20247.6.19Medium
*-7.6.15wpDiscuz <= 7.6.15 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Alternative TextApril 22, 20247.6.16Medium
*-7.6.12wpDiscuz <= 7.6.12 - Authenticated (Administrator+) Stored Cross-Site ScriptingNovember 17, 20237.6.13Medium
*-7.6.11wpDiscuz <= 7.6.11 - Cross-Site Request ForgeryNovember 14, 20237.6.12Medium
*-7.6.11wpDiscuz <= 7.6.11 - Unauthenticated Stored Cross-Site Scripting via Comment Uploaded Image FilenameOctober 31, 20237.6.12High
*-7.6.10wpDiscuz <= 7.6.10 - Unauthenticated Content InjectionOctober 22, 20237.6.11Medium
*-7.6.3wpDiscuz <= 7.6.3 - Authenticated(Author+) Insecure Direct Object ReferenceOctober 22, 20237.6.4Low
*-7.6.10wpDiscuz <= 7.6.10 - Insufficient Authorization to Comment Submission on Deleted PostsOctober 20, 20237.6.11Medium
*-7.6.3wpDiscuz <= 7.6.3 - Missing Authorization via AJAX actionsOctober 12, 20237.6.4Medium
[*, 7.6.6)wpDiscuz <= 7.6.5 - Unauthenticated SQL InjectionSeptember 18, 20237.6.6High
*-7.6.3wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Comment Rating Increase/DecreaseSeptember 12, 20237.6.4Medium
*-7.6.3wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Post Rating Increase/DecreaseSeptember 12, 20237.6.4Medium
*-7.4.2Comments – wpDiscuz <= 7.4.2 - Insecure Direct Object ReferencesOctober 28, 20227.5Medium
*-7.3.11Comments - wpDiscuz <= 7.3.11 Sensitive Information DisclosureFebruary 10, 20227.3.12Low
[*, 7.3.4)Comments - wpDiscuz <= 7.3.3 - Arbitrary Comment Addition/Edition/Deletion by Cross-Site Request ForgeryOctober 11, 20217.3.4Medium
*-7.3.0Comments - wpDiscuz <= 7.3.0 - Authenticated Stored Cross-Site ScriptingSeptember 13, 20217.3.2Medium
7.0-7.0.4Comments - wpDiscuz 7.0 - 7.0.4 - Unauthenticated Arbitrary File Upload leading to Remote Code ExecutionJune 6, 20217.0.5Critical
[*, 5.3.6)Comments - wpDiscuz <= 5.3.5 - Blind SQL Injection via order ParameterJune 12, 20205.3.6Critical

Selected source records

Latest Records

HighCVE-2026-9148

Comments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website' Field

Published: July 2, 2026

Affected versions
*-7.6.56
Patched versions
7.6.57
Original Wordfence record
MediumCVE-2026-22209

Comments – wpDiscuz <= 7.6.46 - Authenticated (Admin+) Stored Cross-Site Scripting

Published: March 12, 2026

Affected versions
*-7.6.46
Patched versions
7.6.47
Original Wordfence record
MediumCVE-2025-68997

wpDiscuz <= 7.6.42 - Unauthenticated Insecure Direct Object Reference

Published: December 25, 2025

Affected versions
*-7.6.42
Patched versions
7.6.44
Original Wordfence record
HighCVE-2025-13820

Comments – wpDiscuz <= 7.6.39 - Unauthenticated Authentication Bypass Through Account Takeover

Published: December 11, 2025

Affected versions
*-7.6.39
Patched versions
7.6.40
Original Wordfence record
MediumCVE-2025-59591

wpDiscuz <= 7.6.33 - Missing Authorization

Published: September 22, 2025

Affected versions
*-7.6.33
Patched versions
7.6.34
Original Wordfence record
CriticalCVE-2024-9488

Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider

Published: October 24, 2024

Affected versions
*-7.6.24
Patched versions
7.6.25
Original Wordfence record
MediumCVE-2024-6704

Comments – wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection

Published: August 1, 2024

Affected versions
*-7.6.21
Patched versions
7.6.22
Original Wordfence record
MediumCVE-2024-35681

Comments – wpDiscuz <= 7.6.18 - Authenticated (Contributor+) Stored Cross-Site Scripting

Published: June 6, 2024

Affected versions
*-7.6.18
Patched versions
7.6.19
Original Wordfence record

Highest-Severity Records

CriticalCVE-2020-13640

Comments - wpDiscuz <= 5.3.5 - Blind SQL Injection via order Parameter

Published: June 12, 2020

Affected versions
[*, 5.3.6)
Patched versions
5.3.6
Original Wordfence record
CriticalCVE-2024-9488

Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider

Published: October 24, 2024

Affected versions
*-7.6.24
Patched versions
7.6.25
Original Wordfence record
CriticalCVE-2020-24186

Comments - wpDiscuz 7.0 - 7.0.4 - Unauthenticated Arbitrary File Upload leading to Remote Code Execution

Published: June 6, 2021

Affected versions
7.0-7.0.4
Patched versions
7.0.5
Original Wordfence record
High

wpDiscuz <= 7.6.5 - Unauthenticated SQL Injection

Published: September 18, 2023

Affected versions
[*, 7.6.6)
Patched versions
7.6.6
Original Wordfence record
HighCVE-2025-13820

Comments – wpDiscuz <= 7.6.39 - Unauthenticated Authentication Bypass Through Account Takeover

Published: December 11, 2025

Affected versions
*-7.6.39
Patched versions
7.6.40
Original Wordfence record
HighCVE-2023-47185

wpDiscuz <= 7.6.11 - Unauthenticated Stored Cross-Site Scripting via Comment Uploaded Image Filename

Published: October 31, 2023

Affected versions
*-7.6.11
Patched versions
7.6.12
Original Wordfence record
HighCVE-2026-9148

Comments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website' Field

Published: July 2, 2026

Affected versions
*-7.6.56
Patched versions
7.6.57
Original Wordfence record
MediumCVE-2024-35681

Comments – wpDiscuz <= 7.6.18 - Authenticated (Contributor+) Stored Cross-Site Scripting

Published: June 6, 2024

Affected versions
*-7.6.18
Patched versions
7.6.19
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory