Wpdiscuz
Vendor:
First CVE: Jun 18, 2020 · Active for 6 years
33
Total CVEs
More Total CVEs than 96% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wpdiscuz over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 18, 2020
6 years ago
Most Recent CVE
Mar 13, 2026
134 days ago
CVE Severity & Scoring
Wpdiscuz33 CVEs
64%
24%
12%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network32 (97.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.0%)
Attack Complexity
Low33 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None20 (60.6%)
Unknown0 (0.0%)
Required13 (39.4%)
Privileges Required
Low5 (15.2%)
High4 (12.1%)
None24 (72.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24186CRITICAL A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, includi | Aug 24, 2020 | 10.0 | 93 | NO | YES |
CVE-2020-13640CRITICAL A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoad | Jun 18, 2020 | 9.8 | 46 | NO | YES |
CVE-2026-22192CRITICAL Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipula | Mar 13, 2026 | 9.9 | 36 | NO | NO |
CVE-2026-22199HIGH Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitra | Mar 13, 2026 | 7.5 | 31 | NO | NO |
CVE-2024-9488CRITICAL The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the us | Oct 25, 2024 | 9.8 | 30 | NO | NO |
CVE-2022-43492HIGH Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress. | Nov 18, 2022 | 8.8 | 27 | NO | NO |
CVE-2026-22193HIGH wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escaping in SQL queries. Attackers ca | Mar 13, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-22182HIGH wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the checkNotificati | Mar 13, 2026 | 7.5 | 25 | NO | NO |
CVE-2023-47775HIGH Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions. | Nov 22, 2023 | 8.8 | 24 | NO | NO |
CVE-2026-22202MEDIUM wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET | Mar 13, 2026 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (33 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.0% of CVEs· 96th percentile
Nuclei
2 CVEs
6.1% of CVEs· 97th percentile
ExploitDB
1 CVE
3.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (33 CVEs).
Media Mentions
Signals from CVEs in this product scope (33 CVEs).
Top CNAs Publishing CVEs For Wpdiscuz
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.4.2 | 1 | 8.8 | 0.6% | 0 | 0 |