VendorsgVectorswpdiscuzall versions
Vulnerabilities

gVectors wpDiscuz

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

33CVEs
CVE-2020-24186
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
Published 2020-08-24 · Modified
10.02 PoCEPSS 0.946
CVE-2026-22192
Voltronic Power SNMP Web Pro 1.1 Authentication Bypass via localStorage
Published 2026-03-13 · Modified
9.9EPSS 0.003
CVE-2020-13640
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)
Published 2020-06-18 · Modified
9.8EPSS 0.126
CVE-2024-9488
Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider
Published 2024-10-25 · Analyzed
9.8EPSS 0.008
CVE-2026-22193
wpDiscuz before 7.6.47 - SQL Injection in getAllSubscriptions()
Published 2026-03-13 · Analyzed
9.2EPSS 0.003
CVE-2022-43492
WordPress Comments – wpDiscuz plugin 7.4.2 - Auth. Insecure Direct Object References (IDOR) vulnerability
Published 2022-11-18 · Modified
8.8EPSS 0.007
CVE-2023-45760
WordPress wpDiscuz plugin <= 7.6.3 - Broken Access Control vulnerability
Published 2025-01-02 · Modified
8.8EPSS 0.004
CVE-2023-47775
WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-11-22 · Modified
8.8EPSS 0.003
CVE-2026-22199
Voltronic Power SNMP Web Pro 1.1 Path Traversal via upload.cgi
Published 2026-03-13 · Modified
8.7EPSS 0.010
CVE-2026-22182
wpDiscuz before 7.6.47 - Unauthenticated Email Notification Flood via wpdCheckNotificationType
Published 2026-03-13 · Analyzed
8.7EPSS 0.005
CVE-2026-22202
wpDiscuz before 7.6.47 - Destructive GET Action Deletes All Comments by Email
Published 2026-03-13 · Analyzed
8.1EPSS 0.002
CVE-2022-23984
WordPress wpDiscuz plugin <= 7.3.11 - Sensitive Information Disclosure
Published 2022-02-21 · Modified
7.5EPSS 0.011
CVE-2023-46309
WordPress wpDiscuz plugin <= 7.6.10 - Broken Access Control vulnerability
Published 2025-01-02 · Modified
7.3EPSS 0.004
CVE-2023-47185
WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Scripting (XSS)
Published 2023-11-06 · Modified
7.1EPSS 0.004
CVE-2026-22216
wpDiscuz before 7.6.47 - No Rate Limiting on Subscription Endpoints with LIKE Wildcard Bypass
Published 2026-03-13 · Analyzed
6.9EPSS 0.003
CVE-2026-22203
wpDiscuz before 7.6.47 - Options Export Leaks OAuth Secrets in Plaintext
Published 2026-03-13 · Analyzed
6.9EPSS 0.003
CVE-2026-22201
wpDiscuz before 7.6.47 - IP Address Spoofing in getIP()
Published 2026-03-13 · Analyzed
6.9EPSS 0.002
CVE-2023-46311
WordPress wpDiscuz Plugin <= 7.6.3 is vulnerable to Insecure Direct Object References (IDOR)
Published 2023-12-20 · Modified
6.5EPSS 0.005
CVE-2024-35681
WordPress wpDiscuz plugin <= 7.6.18 - Cross Site Scripting (XSS) vulnerability
Published 2024-06-08 · Modified
6.5EPSS 0.003
CVE-2024-2477
wpDiscuz <= 7.6.15 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Alternative Text
Published 2024-04-23 · Modified
6.4EPSS 0.003
CVE-2026-22204
wpDiscuz before 7.6.47 - Unsanitized Cookie Email Used as wp_mail() Recipient
Published 2026-03-13 · Analyzed
6.3EPSS 0.002
CVE-2024-6704
Comments – wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection
Published 2024-08-02 · Analyzed
6.1EPSS 0.006
CVE-2023-46310
WordPress wpDiscuz plugin <= 7.6.10 - Content Injection vulnerability
Published 2024-06-04 · Analyzed
6.1EPSS 0.003
CVE-2026-22183
wpDiscuz before 7.6.47 - Stored Cross-Site Scripting in Inline Comment Preview
Published 2026-03-13 · Analyzed
6.1EPSS 0.002
CVE-2026-22210
wpDiscuz before 7.6.47 - Cross-Site Scripting via Unescaped Attachment URLs
Published 2026-03-13 · Analyzed
6.1EPSS 0.002
CVE-2023-51691
WordPress wpDiscuz Plugin <= 7.6.12 is vulnerable to Cross Site Scripting (XSS)
Published 2024-02-01 · Modified
5.9EPSS 0.003
CVE-2026-22209
wpDiscuz before 7.6.47 - Cross-Site Scripting via Unescaped Custom CSS in Style Tag
Published 2026-03-13 · Modified
5.5EPSS 0.002
CVE-2026-22215
wpDiscuz before 7.6.47 - Missing CSRF Protection on wpdGetFollowsPage
Published 2026-03-13 · Analyzed
5.4EPSS 0.002
CVE-2023-3998
wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Post Rating Increase/Decrease
Published 2023-10-20 · Modified
5.3EPSS 0.005
CVE-2023-3869
wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Comment Rating Increase/Decrease
Published 2023-10-20 · Modified
5.3EPSS 0.005
CVE-2026-22191
Beghelli Sicuro24 SicuroWeb AngularJS Template Injection
Published 2026-03-13 · Modified
5.2EPSS 0.004
CVE-2021-24737
Comments - wpDiscuz <= 7.3.0 - Admin+ Stored Cross-Site Scripting
Published 2021-10-11 · Modified
4.8EPSS 0.006
CVE-2021-24806
wpDiscuz < 7.3.4 - Arbitrary Comment Addition/Edition/Deletion via CSRF
Published 2021-11-08 · Modified
4.3EPSS 0.005