CVE-2021-24806
The wpDiscuz plugin before version 7.3.4 fails to implement CSRF protections on multiple comment-related functions, allowing attackers to trick authenticated users into performing unwanted actions. Specifically, an attacker could exploit this vulnerability to cause administrators or comment authors to add, edit, or delete comments without their knowledge, as well as manipulate thread status through the wpdCloseThread action and comment visibility through the wpdStickComment action. Any authenticated user, including site administrators, could be targeted by a malicious actor crafting requests that execute these operations when the user visits a compromised page.
Based on public CVE data (MITRE/NVD).