CVE-2026-22201
Published
CVSS v3
5.3
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban enforcement by trusting untrusted HTTP headers. Attackers can set HTTP_CLIENT_IP or HTTP_X_FORWARDED_FOR headers to spoof their IP address and circumvent security controls.
<p>wpDiscuz is an advanced AJAX-powered WordPress comments plugin that upgrades the default WordPress comment system with live commenting, comment voting, inline feedback, social login, custom comment forms, and modern engagement-focused features.</p>
<p>Perfect as a modern Disqus alternative while keeping all comments stored securely in your own WordPress database.</p>
<p>Designed to supercharge WordPress native comments, wpDiscuz delivers a fast, lightweight, and highly interactive commenting experience for blogs, news websites, magazines, communities, membership sites, and WooCommerce stores.</p>
<p>wpDiscuz version 7 introduces a revolutionary approach to WordPress commenting with innovative engagement tools, optimized AJAX performance, lazy-loaded comments, and a modern responsive design.</p>
<ul>
<li>wpDiscuz Demo: <a href="https://wpdiscuz.com/" rel="nofollow ugc">https://wpdiscuz.com/</a></li>
<li>Support Forum: <a href="https://wpdiscuz.com/community/" rel="nofollow ugc">https://wpdiscuz.com/community/</a></li>
<li>wpDiscuz GDPR: <a href="https://wpdiscuz.com/gdpr/" rel="nofollow ugc">https://wpdiscuz.com/gdpr/</a></li>
<li>wpDiscuz Addons: <a href="https://wpdiscuz.com/addons/" rel="nofollow ugc">https://wpdiscuz.com/addons/</a></li>
<li>wpDiscuz Documentation: <a href="https://wpdiscuz.com/docs/" rel="nofollow ugc">https://wpdiscuz.com/docs/</a></li>
<li>wpDiscuz Addons Bundle: <a href="https://gvectors.com/product/wpdiscuz-addons-bundle/" rel="nofollow ugc">https://gvectors.com/product/wpdiscuz-addons-bundle/</a></li>
</ul>
<h4>Live AJAX Comments</h4>
<p>Enable fast AJAX-powered live comments for WordPress with instant comment posting, smooth interactions, and real-time updates without page reloads.</p>
<h4>Inline Commenting and Feedback</h4>
<p>Allow users to comment directly on post content and provide inline feedback for better discussions and higher user engagement.</p>
<h4>Comment Voting and Rating</h4>
<p>Boost community interaction with upvote/downvote comment voting, comment rating, and post rating features.</p>
<h4>Social Login and Social Comments</h4>
<p>Allow users to comment using popular social login providers like Facebook and Twitter for a faster commenting experience.</p>
<h4>Custom WordPress Comment Forms</h4>
<p>Create custom comment forms and fields for different post types, products, pages, communities, and discussions.</p>
<h4>WooCommerce Comment Integration</h4>
<p>Improve WooCommerce product discussions and customer engagement with modern AJAX-powered product comments and rating features.</p>
<h4>Fast and Lightweight WordPress Comments</h4>
<p>wpDiscuz is optimized for speed with lazy-loaded comments, built-in caching, AJAX posting, and performance-focused architecture.</p>
<h4>Disqus Alternative for WordPress</h4>
<p>Replace Disqus, Jetpack Comments, and other third-party comment systems while keeping full ownership of your comments and user data.</p>
<h4>Comments – wpDiscuz Features</h4>
<ul>
<li>Three modern WordPress comment layouts</li>
<li>Fast AJAX-powered WordPress comments</li>
<li>Interactive live comment form for WordPress</li>
<li>Inline commenting and inline feedback</li>
<li>Live notifications with real-time comment bubble updates</li>
<li>Social commenting with multiple social login options</li>
<li>Post rating and comment rating features</li>
<li>Responsive WordPress comment forms and comment threads</li>
<li>Modern user interface and user experience</li>
<li>Comment sorting by newest, oldest, and most voted comments</li>
<li>Anonymous WordPress comments support</li>
<li>Integration with social network login plugins</li>
<li>Multi-level nested comment threads</li>
<li>AJAX “Load More Comments” button</li>
<li>Lazy load WordPress comments on scroll</li>
<li>WordPress date format integration</li>
<li>Comment editing for logged-in users and guests</li>
<li>Automatic URL and image embedding in comments</li>
<li>Long comment collapsing with “Read More” button</li>
<li>Comment subscription and notification options</li>
<li>AJAX comment form validation and posting</li>
<li>Fully integrated with WordPress native comments</li>
<li>Secure anti-spam WordPress comment system</li>
<li>Positive and negative comment voting</li>
<li>Smart voting system with cookies and user tracking</li>
<li>Quick Tags support for comments</li>
<li>Custom WordPress comment forms and custom fields</li>
<li>Highlighting new comments since last visit</li>
<li>Notifications when comments are approved</li>
<li>View replies button for nested comments</li>
<li>Comment access control by user roles</li>
<li>Option to load all comments on first page load</li>
<li>Built-in Gravatar caching</li>
<li>Sticky comments support</li>
<li>Closed comment threads support</li>
<li>User follow and subscriptions</li>
<li>Built-in comment and author caching system</li>
</ul>
<h4>Add-ons</h4>
<ul>
<li>| <a href="https://gvectors.com/product/wpdiscuz-addons-bundle/" rel="nofollow ugc">wpDiscuz – Bundle</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-reviews/" rel="nofollow ugc">wpDiscuz – Reviews</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-emoticons/" rel="nofollow ugc">wpDiscuz – Emoticons</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-user-notifications/" rel="nofollow ugc">wpDiscuz – User Notifications</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-media-uploader/" rel="nofollow ugc">wpDiscuz – Media Uploader</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-embeds/" rel="nofollow ugc">wpDiscuz – Embeds</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-comment-author-info/" rel="nofollow ugc">wpDiscuz – Comment Author Info</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-recaptcha/" rel="nofollow ugc">wpDiscuz – Google ReCaptcha</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-mycred/" rel="nofollow ugc">wpDiscuz – myCRED Integration</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-widgets/" rel="nofollow ugc">wpDiscuz – Widgets</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-frontend-moderation/" rel="nofollow ugc">wpDiscuz – Front-end Moderation</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-subscribe-manager/" rel="nofollow ugc">wpDiscuz – Subscription Manager</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-comment-search/" rel="nofollow ugc">wpDiscuz – Comment Search</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-report-flagging/" rel="nofollow ugc">wpDiscuz – Comment Report and Flagging</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-ads-manager/" rel="nofollow ugc">wpDiscuz – Ads Manager</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-user-comment-mentioning/" rel="nofollow ugc">wpDiscuz – User & Comment Mentioning</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-advanced-likers/" rel="nofollow ugc">wpDiscuz – Advanced Likers</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-online-users/" rel="nofollow ugc">wpDiscuz – Online Users</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-private-comments/" rel="nofollow ugc">wpDiscuz – Private Comments</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-syntax-highlighter/" rel="nofollow ugc">wpDiscuz – Syntax Highlighter</a></li>
<li>| <a href="https://gvectors.com/product/comments-censure-pro/" rel="nofollow ugc">Comments Censure PRO</a></li>
</ul>
<h4>Integration Add-ons</h4>
<ul>
<li>| <a href="https://gvectors.com/product/wpdiscuz-buddypress-integration/" rel="nofollow ugc">wpDiscuz – BuddyPress Integration</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-giphy-integration/" rel="nofollow ugc">wpDiscuz – GIPHY Integration</a></li>
<li>| <a href="https://gvectors.com/product/wpdiscuz-voice-commenting/" rel="nofollow ugc">wpDiscuz – Voice Commenting</a></li>
</ul>