CVE · Medium

CVE-2025-68997 — Comments – wpDiscuz [wpdiscuz] < 7.6.44

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-68997 Comments – wpDiscuz [wpdiscuz] < 7.6.44 Authorization Bypass Through User-Controlled Key Medium 5.3 < 7.6.44 7.6.44 2025-12-25

CVE-2025-68997

The wpDiscuz plugin for WordPress, up to version 7.6.42, is susceptible to Insecure Direct Object Reference vulnerabilities because it lacks proper validation of a user-controlled key. This flaw allows unauthenticated users to carry out unintended operations.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.