PLUGIN SECURITY
Is Anycomment safe?
AnyComment is blazing-fast commenting plugin based on React for WordPress.
What this plugin does
- Slug:
anycomment - Author: Alexander
- 5000+ active installs
- 96/100 rating (156 reviews on wordpress.org)
- 98093 all-time downloads
- On WordPress.org since 2018-06-24
ajax commentscommentcomment moderationcommentsComments SEO
Maintenance status
- Latest known version: 0.3.6
- Last updated: 2022-05-14 8:15pm GMT
- Tested up to WordPress: 5.9.16
- Requires PHP: 5.4+
- Max supported PHP (analyzed): <8.0
⚠ Anycomment hasn't been updated in over 1570 days. An unmaintained plugin doesn't receive new security fixes, which is itself a security risk even without a known CVE.
Known vulnerabilities
8 known CVEs on file for Anycomment. Reported between 2018 and 2025.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | AnyComment [anycomment] <= 0.3.6 (unfixed) | Missing Authorization | Unknown | < 0.3.6 | 0.3.6 | 2025-12-31 | ✓ fixed in latest |
| CVE-2025-48091 | AnyComment [anycomment] <= 0.3.6 (unfixed) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.5 | < 0.3.6 | 0.3.6 | 2025-10-08 | ✓ fixed in latest |
| CVE-2025-60240 | AnyComment [anycomment] <= 0.3.6 (unfixed) | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | High 7.5 | < 0.3.6 | 0.3.6 | 2025-07-12 | ✓ fixed in latest |
| CVE-2023-33999 | AnyComment [anycomment] < 0.0.99 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 0.0.99 | 0.0.99 | 2023-07-18 | ✓ fixed in latest |
| CVE-2022-0134 | AnyComment [anycomment] < 0.2.18 | Cross-Site Request Forgery (CSRF) | High 8.8 | < 0.2.18 | 0.2.18 | 2022-01-19 | ✓ fixed in latest |
| CVE-2022-0279 | AnyComment [anycomment] < 0.2.18 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | Low 3.1 | < 0.2.18 | 0.2.18 | 2022-01-19 | ✓ fixed in latest |
| CVE-2021-24838 | AnyComment [anycomment] < 0.3.5 | URL Redirection to Untrusted Site ('Open Redirect') | Medium 6.1 | < 0.3.5 | 0.3.5 | 2021-12-20 | ✓ fixed in latest |
| CVE-2018-21001 | AnyComment [anycomment] < 0.0.33 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 0.0.33 | 0.0.33 | 2018-07-17 | ✓ fixed in latest |
+ 1 more known vulnerability
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-62874 | AnyComment <= 0.3.6 - Missing Authorization | — | Unknown | not specified | no fix on file | — | — |
How to fix it
Keep Anycomment updated — 0.3.6 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
1 of the vulnerabilities above has no fixed version on file — there's no update that resolves it. Consider deactivating this plugin or switching to one of the alternatives below.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Comments – wpDiscuz — 60000+ active installs — 94/100 (578) — max PHP 8.4
- DCO Comment Attachment — 5000+ active installs — 98/100 (10) — max PHP 8.4
- Bulk Delete Comments — 5000+ active installs — 82/100 (12) — max PHP 8.4
- Comments Like Dislike — 5000+ active installs — 92/100 (38)
- One Click Close Comments — 5000+ active installs — 98/100 (10)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.