CVE · Medium

CVE-2025-13820 — Comments – wpDiscuz [wpdiscuz] < 7.6.40

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13820 Comments – wpDiscuz [wpdiscuz] < 7.6.40 Improper Privilege Management Medium 5.3 < 7.6.40 7.6.40 2025-12-11

CVE-2025-13820

The Comments – wpDiscuz plugin for WordPress, up to version 7.6.39, is susceptible to an authentication bypass vulnerability because it fails to adequately validate user identities via the disqus.com provider. This flaw allows unauthenticated attackers to impersonate other users if disqus authentication has not been configured.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.