Disable Comments is a narrowly scoped WordPress plugin focused on comment-management functionality, with vulnerabilities centered on the plugin's administrative interface and state-changing operations. The recurrent weakness class involves cross-site request forgery, reflecting the plugin's need to validate request origins and protect against unauthorized comment-configuration changes. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Disable Comments over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-2550HIGH Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote attackers to hijack the authentication of administrators for | Mar 19, 2018 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Disable Comments.
Media articles that mention a CVE ID that affects a product developed by Disable Comments — matched by CVE ID, not by vendor name.