Cross-Site Scripting
9 records34.6%First: 2016. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 26 vulnerability records associated with Comments – wpDiscuz, published between 2016 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2016 | 1 | |
| 2020 | 1 | |
| 2021 | 3 | |
| 2022 | 2 | |
| 2023 | 10 | |
| 2024 | 4 | |
| 2025 | 3 | |
| 2026 | 2 |
| Severity | Records | Share |
|---|---|---|
| Critical | 3 | 11.5% |
| High | 4 | 15.4% |
| Medium | 16 | 61.5% |
| Low | 2 | 7.7% |
| Informational | 1 | 3.8% |
First: 2016. Latest: 2026.
First: 2022. Latest: 2025.
First: 2020. Latest: 2023.
First: 2021. Latest: 2023.
First: 2021. Latest: 2021.
First: 2022. Latest: 2022.
First: 2023. Latest: 2023.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
7.6.577.6.477.6.447.6.407.6.347.6.257.6.227.6.197.6.167.6.137.6.127.6.47.6.117.6.67.57.3.127.3.47.3.27.0.55.3.63.2.0Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-7.6.56 | Comments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website' Field | July 2, 2026 | 7.6.57 | High |
*-7.6.46 | Comments – wpDiscuz <= 7.6.46 - Authenticated (Admin+) Stored Cross-Site Scripting | March 12, 2026 | 7.6.47 | Medium |
*-7.6.42 | wpDiscuz <= 7.6.42 - Unauthenticated Insecure Direct Object Reference | December 25, 2025 | 7.6.44 | Medium |
*-7.6.39 | Comments – wpDiscuz <= 7.6.39 - Unauthenticated Authentication Bypass Through Account Takeover | December 11, 2025 | 7.6.40 | High |
*-7.6.33 | wpDiscuz <= 7.6.33 - Missing Authorization | September 22, 2025 | 7.6.34 | Medium |
*-7.6.24 | Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider | October 24, 2024 | 7.6.25 | Critical |
*-7.6.21 | Comments – wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection | August 1, 2024 | 7.6.22 | Medium |
*-7.6.18 | Comments – wpDiscuz <= 7.6.18 - Authenticated (Contributor+) Stored Cross-Site Scripting | June 6, 2024 | 7.6.19 | Medium |
*-7.6.15 | wpDiscuz <= 7.6.15 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Alternative Text | April 22, 2024 | 7.6.16 | Medium |
*-7.6.12 | wpDiscuz <= 7.6.12 - Authenticated (Administrator+) Stored Cross-Site Scripting | November 17, 2023 | 7.6.13 | Medium |
*-7.6.11 | wpDiscuz <= 7.6.11 - Cross-Site Request Forgery | November 14, 2023 | 7.6.12 | Medium |
*-7.6.11 | wpDiscuz <= 7.6.11 - Unauthenticated Stored Cross-Site Scripting via Comment Uploaded Image Filename | October 31, 2023 | 7.6.12 | High |
*-7.6.10 | wpDiscuz <= 7.6.10 - Unauthenticated Content Injection | October 22, 2023 | 7.6.11 | Medium |
*-7.6.3 | wpDiscuz <= 7.6.3 - Authenticated(Author+) Insecure Direct Object Reference | October 22, 2023 | 7.6.4 | Low |
*-7.6.10 | wpDiscuz <= 7.6.10 - Insufficient Authorization to Comment Submission on Deleted Posts | October 20, 2023 | 7.6.11 | Medium |
*-7.6.3 | wpDiscuz <= 7.6.3 - Missing Authorization via AJAX actions | October 12, 2023 | 7.6.4 | Medium |
[*, 7.6.6) | wpDiscuz <= 7.6.5 - Unauthenticated SQL Injection | September 18, 2023 | 7.6.6 | High |
*-7.6.3 | wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Comment Rating Increase/Decrease | September 12, 2023 | 7.6.4 | Medium |
*-7.6.3 | wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Post Rating Increase/Decrease | September 12, 2023 | 7.6.4 | Medium |
*-7.4.2 | Comments – wpDiscuz <= 7.4.2 - Insecure Direct Object References | October 28, 2022 | 7.5 | Medium |
*-7.3.11 | Comments - wpDiscuz <= 7.3.11 Sensitive Information Disclosure | February 10, 2022 | 7.3.12 | Low |
[*, 7.3.4) | Comments - wpDiscuz <= 7.3.3 - Arbitrary Comment Addition/Edition/Deletion by Cross-Site Request Forgery | October 11, 2021 | 7.3.4 | Medium |
*-7.3.0 | Comments - wpDiscuz <= 7.3.0 - Authenticated Stored Cross-Site Scripting | September 13, 2021 | 7.3.2 | Medium |
7.0-7.0.4 | Comments - wpDiscuz 7.0 - 7.0.4 - Unauthenticated Arbitrary File Upload leading to Remote Code Execution | June 6, 2021 | 7.0.5 | Critical |
[*, 5.3.6) | Comments - wpDiscuz <= 5.3.5 - Blind SQL Injection via order Parameter | June 12, 2020 | 5.3.6 | Critical |
Selected source records
Published: July 2, 2026
Published: March 12, 2026
Published: December 25, 2025
Published: December 11, 2025
Published: September 22, 2025
Published: October 24, 2024
Published: August 1, 2024
Published: June 6, 2024
Published: June 12, 2020
Published: October 24, 2024
Published: June 6, 2021
Published: September 18, 2023
Published: December 11, 2025
Published: October 31, 2023
Published: July 2, 2026
Published: June 6, 2024
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.