CVE · Medium

CVE-2021-24806 — Comments – wpDiscuz [wpdiscuz] < 7.3.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24806 Comments – wpDiscuz [wpdiscuz] < 7.3.4 Cross-Site Request Forgery (CSRF) Medium 4.3 < 7.3.4 7.3.4 2021-10-11

CVE-2021-24806

The wpDiscuz plugin before version 7.3.4 fails to implement CSRF protections on multiple comment-related functions, allowing attackers to trick authenticated users into performing unwanted actions. Specifically, an attacker could exploit this vulnerability to cause administrators or comment authors to add, edit, or delete comments without their knowledge, as well as manipulate thread status through the wpdCloseThread action and comment visibility through the wpdStickComment action. Any authenticated user, including site administrators, could be targeted by a malicious actor crafting requests that execute these operations when the user visits a compromised page.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.