← back to popular plugins
wordfence / plugin · wpdiscuz
Comments – wpDiscuz
wpdiscuz
total installs
70,000
total vulns
3
critical
0
high
1
medium
2
low
0
latest vuln
—
patched
3
unpatched
0
avg time to patch
—
vulnerabilities
(3)
wpDiscuz <= 7.6.42 - Unauthenticated Insecure Direct Object Reference
medium
✓ patched
cve id
CVE-2025-68997 ↗
cvss score
5.3
cwe
CWE-639: Authorization Bypass Through User-Controlled Key
published
Dec 25, 2025
The Comments – wpDiscuz plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.6.42 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform unauthorized actions.
Comments – wpDiscuz <= 7.6.39 - Unauthenticated Authentication Bypass Through Account Takeover
high
✓ patched
cve id
CVE-2025-13820 ↗
cvss score
8.1
cwe
CWE-639: Authorization Bypass Through User-Controlled Key
published
Dec 11, 2025
The Comments – wpDiscuz plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.6.39. This is due to the plugin not properly validating a user's identity through the disqus.com provider. This makes it possible for unauthenticated attackers to authenticate as other users if they have not set up disqus.
wpDiscuz <= 7.6.33 - Missing Authorization
medium
✓ patched
The Comments – wpDiscuz plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.6.33. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.