CVE-2026-22201
Comments – wpDiscuz
Minimum safe version
7.6.47
Update to 7.6.47 or later to address 46 fixable vulnerabilities
CVE-2026-22199
CVE-2026-22193
CVE-2026-22192
CVE-2026-22183
CVE-2026-22191
CVE-2026-22182
CVE-2026-22202
CVE-2026-22203
CVE-2026-22204
CVE-2026-22216
CVE-2026-22209
CVE-2026-22210
CVE-2026-22215
CVE-2025-13820
CVE-2025-68997
WordPress wpDiscuz Plugin <= 7.6.33 is vulnerable to Broken Access Control
CVE-2024-9488
CVE-2024-6704
CVE-2024-35681
CVE-2024-2477
wpDiscuz < 7.6.6 - Unauthenticated SQL Injection
wpDiscuz < 7.6.6 - Unauthenticated SQL Injection
WordPress wpDiscuz Plugin <= 7.6.12 is vulnerable to Cross Site Scripting (XSS)
wpDiscuz <= 7.6.12 - Authenticated (Administrator+) Stored Cross-Site Scripting
CVE-2023-47775
CVE-2023-47185
wpDiscuz <= 7.6.11 - Unauthenticated Stored Cross-Site Scripting via Comment Uploaded Image Filename
CVE-2023-46311
CVE-2023-46310
CVE-2023-46309
wpDiscuz <= 7.6.10 - Insufficient Authorization to Comment Submission on Deleted Posts
CVE-2023-45760
WordPress wpDiscuz Plugin < 7.6.6 is vulnerable to SQL Injection
wpDiscuz <= 7.6.5 - Unauthenticated SQL Injection
CVE-2023-3998
CVE-2023-3869
wpDiscuz <= 3.1.4 - Reflected Cross-Site Scripting (XSS)
Comments - wpDiscuz <= 3.1.4 - Reflected Cross-Site Scripting
CVE-2022-43492
WordPress wpDiscuz Plugin <= 3.1.4 - Reflected Cross Site Scripting (XSS)
WordPress wpDiscuz plugin <= 3.2.8 - Cross-Site Request Forgery (CSRF) Vulnerability
CVE-2020-13640
Comments - wpDiscuz 7.0 - 7.0.4 - Unauthenticated Arbitrary File Upload leading to Remote Code Execution
CVE-2021-24737
CVE-2021-24806
CVE-2022-23984