Wpdiscuz

Vendor:

First CVE: Jun 18, 2020 · Active for 6 years

33
Total CVEs
More Total CVEs than 96% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Wpdiscuz over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 18, 2020
6 years ago
Most Recent CVE
Mar 13, 2026
134 days ago

CVE Severity & Scoring

Wpdiscuz33 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network32 (97.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.0%)
Attack Complexity
Low33 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None20 (60.6%)
Unknown0 (0.0%)
Required13 (39.4%)
Privileges Required
Low5 (15.2%)
High4 (12.1%)
None24 (72.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, includi
Aug 24, 202010.093NOYES
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoad
Jun 18, 20209.846NOYES
Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipula
Mar 13, 20269.936NONO
Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitra
Mar 13, 20267.531NONO
The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the us
Oct 25, 20249.830NONO
Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.
Nov 18, 20228.827NONO
wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escaping in SQL queries. Attackers ca
Mar 13, 20267.526NONO
wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the checkNotificati
Mar 13, 20267.525NONO
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions.
Nov 22, 20238.824NONO
wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET
Mar 13, 20266.523NONO

Exploit Exposure

Signals from CVEs in this product scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.0% of CVEs· 96th percentile
Nuclei
2 CVEs
6.1% of CVEs· 97th percentile
ExploitDB
1 CVE
3.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (33 CVEs).

Media Mentions

Signals from CVEs in this product scope (33 CVEs).

Top CNAs Publishing CVEs For Wpdiscuz

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.4.218.80.6%00