Gvectors

Wpdiscuz

33 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 13.03.2026 01:18:16
  • Zuletzt bearbeitet 17.03.2026 11:43:07

wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to subscribe arbitrary email addresses to post notifications by sending POST requests to the wpdAddSubscription handler in class.WpdiscuzHelpe...

  • EPSS 0.02%
  • Veröffentlicht 13.03.2026 01:18:15
  • Zuletzt bearbeitet 17.03.2026 11:44:28

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that allows attackers to trigger unauthorized actions without nonce validation. Attackers can craft malicious requests to enumerate follow rel...

  • EPSS 0.04%
  • Veröffentlicht 13.03.2026 01:18:14
  • Zuletzt bearbeitet 17.03.2026 11:45:35

wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through unescaped attachment URLs in HTML output by exploiting the WpdiscuzHelperUpload class. Attackers can craft malicious attachmen...

  • EPSS 0.03%
  • Veröffentlicht 13.03.2026 01:18:13
  • Zuletzt bearbeitet 26.03.2026 19:16:32

wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators to inject malicious scripts by breaking out of style tags. Attackers with admin access can inject payloads like </style><script>ale...

  • EPSS 0.05%
  • Veröffentlicht 13.03.2026 01:18:11
  • Zuletzt bearbeitet 17.03.2026 11:47:27

wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious data into the comment_author_email cookie. Attackers can craft a malicious cookie value that, when proc...

  • EPSS 0.05%
  • Veröffentlicht 13.03.2026 01:18:09
  • Zuletzt bearbeitet 17.03.2026 20:23:48

wpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertently expose OAuth secrets by exporting plugin options as JSON. Attackers can obtain exported files containing plaintext API secrets like fb...

  • EPSS 0.02%
  • Veröffentlicht 13.03.2026 01:18:08
  • Zuletzt bearbeitet 17.03.2026 20:24:54

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments...

  • EPSS 0.02%
  • Veröffentlicht 13.03.2026 01:18:07
  • Zuletzt bearbeitet 17.03.2026 20:25:44

wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban enforcement by trusting untrusted HTTP headers. Attackers can set HTTP_CLIENT_IP or HTTP_X_FORWARDED_F...

  • EPSS 0.04%
  • Veröffentlicht 13.03.2026 01:18:06
  • Zuletzt bearbeitet 17.03.2026 20:26:29

wpDiscuz before 7.6.47 contains a vote manipulation vulnerability that allows attackers to manipulate comment votes by obtaining fresh nonces and bypassing rate limiting through client-controlled headers. Attackers can vary User-Agent headers to rese...

  • EPSS 0.03%
  • Veröffentlicht 13.03.2026 01:18:05
  • Zuletzt bearbeitet 17.03.2026 20:27:42

wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escaping in SQL queries. Attackers can inject malicious SQL code through email, activation_key, subscriptio...