PLUGIN SECURITY

Is Comment Form safe?

Advanced Comment Form lets you customize plenty of things on the default comment forms in WordPress.

What this plugin does

  • Slug: comment-form
  • Author: Rock Solid
  • 4000+ active installs
  • 100/100 rating (19 reviews on wordpress.org)
  • 73127 all-time downloads
  • On WordPress.org since 2014-06-23

comment formcommentsform

Maintenance status

  • Latest known version: 1.2.3
  • Last updated: 2024-06-06 8:28am GMT
  • Tested up to WordPress: 6.5.10
  • Requires PHP: 7.2+
  • Max supported PHP (analyzed): 8.4

⚠ Comment Form hasn't been updated in over 816 days. An unmaintained plugin doesn't receive new security fixes, which is itself a security risk even without a known CVE.

Known vulnerabilities

1 known CVE on file for Comment Form. Reported between 2022 and 2022.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3220 Advanced Comment Form [comment-form] < 1.2.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.2.1 1.2.1 2022-09-15 ✓ fixed in latest

How to fix it

Keep Comment Form updated — 1.2.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.