PLUGIN SECURITY

Is Anycomment safe?

AnyComment is blazing-fast commenting plugin based on React for WordPress.

What this plugin does

  • Slug: anycomment
  • Author: Alexander
  • 5000+ active installs
  • 96/100 rating (156 reviews on wordpress.org)
  • 98093 all-time downloads
  • On WordPress.org since 2018-06-24

ajax commentscommentcomment moderationcommentsComments SEO

Maintenance status

  • Latest known version: 0.3.6
  • Last updated: 2022-05-14 8:15pm GMT
  • Tested up to WordPress: 5.9.16
  • Requires PHP: 5.4+
  • Max supported PHP (analyzed): <8.0

⚠ Anycomment hasn't been updated in over 1570 days. An unmaintained plugin doesn't receive new security fixes, which is itself a security risk even without a known CVE.

Known vulnerabilities

8 known CVEs on file for Anycomment. Reported between 2018 and 2025.

CVE Vulnerability Type Severity Affected Fixed in Published Status
AnyComment [anycomment] <= 0.3.6 (unfixed) Missing Authorization Unknown < 0.3.6 0.3.6 2025-12-31 ✓ fixed in latest
CVE-2025-48091 AnyComment [anycomment] <= 0.3.6 (unfixed) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.5 < 0.3.6 0.3.6 2025-10-08 ✓ fixed in latest
CVE-2025-60240 AnyComment [anycomment] <= 0.3.6 (unfixed) Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 7.5 < 0.3.6 0.3.6 2025-07-12 ✓ fixed in latest
CVE-2023-33999 AnyComment [anycomment] < 0.0.99 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 0.0.99 0.0.99 2023-07-18 ✓ fixed in latest
CVE-2022-0134 AnyComment [anycomment] < 0.2.18 Cross-Site Request Forgery (CSRF) High 8.8 < 0.2.18 0.2.18 2022-01-19 ✓ fixed in latest
CVE-2022-0279 AnyComment [anycomment] < 0.2.18 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Low 3.1 < 0.2.18 0.2.18 2022-01-19 ✓ fixed in latest
CVE-2021-24838 AnyComment [anycomment] < 0.3.5 URL Redirection to Untrusted Site ('Open Redirect') Medium 6.1 < 0.3.5 0.3.5 2021-12-20 ✓ fixed in latest
CVE-2018-21001 AnyComment [anycomment] < 0.0.33 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 0.0.33 0.0.33 2018-07-17 ✓ fixed in latest
+ 1 more known vulnerability
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-62874 AnyComment <= 0.3.6 - Missing Authorization Unknown not specified no fix on file

How to fix it

Keep Anycomment updated — 0.3.6 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

1 of the vulnerabilities above has no fixed version on file — there's no update that resolves it. Consider deactivating this plugin or switching to one of the alternatives below.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.