CVE · Medium

CVE-2023-3998 — Comments – wpDiscuz [wpdiscuz] < 7.6.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-3998 Comments – wpDiscuz [wpdiscuz] < 7.6.4 Authorization Bypass Through User-Controlled Key Medium 5.3 < 7.6.4 7.6.4 2023-09-12

CVE-2023-3998

The wpDiscuz plugin before version 7.6.4 contains an insecure direct object reference vulnerability that could enable attackers to circumvent security controls and gain unauthorized access to sensitive data or database operations. The flaw was identified by FearZzZz and addresses a situation where direct object references lack proper authorization checks. Users should upgrade to version 7.6.4 or later to remediate this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.