CVE-2026-22202

Published
View on NVD ↗
CVSS v3
8.1
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments action URL in image tags or other resources to trigger permanent deletion of comments without user confirmation or POST-based CSRF protection.

<p>wpDiscuz is an advanced AJAX-powered WordPress comments plugin that upgrades the default WordPress comment system with live commenting, comment voting, inline feedback, social login, custom comment forms, and modern engagement-focused features.</p> <p>Perfect as a modern Disqus alternative while keeping all comments stored securely in your own WordPress database.</p> <p>Designed to supercharge WordPress native comments, wpDiscuz delivers a fast, lightweight, and highly interactive commenting experience for blogs, news websites, magazines, communities, membership sites, and WooCommerce stores.</p> <p>wpDiscuz version 7 introduces a revolutionary approach to WordPress commenting with innovative engagement tools, optimized AJAX performance, lazy-loaded comments, and a modern responsive design.</p> <ul> <li>wpDiscuz Demo: <a href="https://wpdiscuz.com/" rel="nofollow ugc">https://wpdiscuz.com/</a></li> <li>Support Forum: <a href="https://wpdiscuz.com/community/" rel="nofollow ugc">https://wpdiscuz.com/community/</a></li> <li>wpDiscuz GDPR: <a href="https://wpdiscuz.com/gdpr/" rel="nofollow ugc">https://wpdiscuz.com/gdpr/</a></li> <li>wpDiscuz Addons: <a href="https://wpdiscuz.com/addons/" rel="nofollow ugc">https://wpdiscuz.com/addons/</a></li> <li>wpDiscuz Documentation: <a href="https://wpdiscuz.com/docs/" rel="nofollow ugc">https://wpdiscuz.com/docs/</a></li> <li>wpDiscuz Addons Bundle: <a href="https://gvectors.com/product/wpdiscuz-addons-bundle/" rel="nofollow ugc">https://gvectors.com/product/wpdiscuz-addons-bundle/</a></li> </ul> <h4>Live AJAX Comments</h4> <p>Enable fast AJAX-powered live comments for WordPress with instant comment posting, smooth interactions, and real-time updates without page reloads.</p> <h4>Inline Commenting and Feedback</h4> <p>Allow users to comment directly on post content and provide inline feedback for better discussions and higher user engagement.</p> <h4>Comment Voting and Rating</h4> <p>Boost community interaction with upvote/downvote comment voting, comment rating, and post rating features.</p> <h4>Social Login and Social Comments</h4> <p>Allow users to comment using popular social login providers like Facebook and Twitter for a faster commenting experience.</p> <h4>Custom WordPress Comment Forms</h4> <p>Create custom comment forms and fields for different post types, products, pages, communities, and discussions.</p> <h4>WooCommerce Comment Integration</h4> <p>Improve WooCommerce product discussions and customer engagement with modern AJAX-powered product comments and rating features.</p> <h4>Fast and Lightweight WordPress Comments</h4> <p>wpDiscuz is optimized for speed with lazy-loaded comments, built-in caching, AJAX posting, and performance-focused architecture.</p> <h4>Disqus Alternative for WordPress</h4> <p>Replace Disqus, Jetpack Comments, and other third-party comment systems while keeping full ownership of your comments and user data.</p> <h4>Comments &#8211; wpDiscuz Features</h4> <ul> <li>Three modern WordPress comment layouts</li> <li>Fast AJAX-powered WordPress comments</li> <li>Interactive live comment form for WordPress</li> <li>Inline commenting and inline feedback</li> <li>Live notifications with real-time comment bubble updates</li> <li>Social commenting with multiple social login options</li> <li>Post rating and comment rating features</li> <li>Responsive WordPress comment forms and comment threads</li> <li>Modern user interface and user experience</li> <li>Comment sorting by newest, oldest, and most voted comments</li> <li>Anonymous WordPress comments support</li> <li>Integration with social network login plugins</li> <li>Multi-level nested comment threads</li> <li>AJAX &#8220;Load More Comments&#8221; button</li> <li>Lazy load WordPress comments on scroll</li> <li>WordPress date format integration</li> <li>Comment editing for logged-in users and guests</li> <li>Automatic URL and image embedding in comments</li> <li>Long comment collapsing with &#8220;Read More&#8221; button</li> <li>Comment subscription and notification options</li> <li>AJAX comment form validation and posting</li> <li>Fully integrated with WordPress native comments</li> <li>Secure anti-spam WordPress comment system</li> <li>Positive and negative comment voting</li> <li>Smart voting system with cookies and user tracking</li> <li>Quick Tags support for comments</li> <li>Custom WordPress comment forms and custom fields</li> <li>Highlighting new comments since last visit</li> <li>Notifications when comments are approved</li> <li>View replies button for nested comments</li> <li>Comment access control by user roles</li> <li>Option to load all comments on first page load</li> <li>Built-in Gravatar caching</li> <li>Sticky comments support</li> <li>Closed comment threads support</li> <li>User follow and subscriptions</li> <li>Built-in comment and author caching system</li> </ul> <h4>Add-ons</h4> <ul> <li>| <a href="https://gvectors.com/product/wpdiscuz-addons-bundle/" rel="nofollow ugc">wpDiscuz &#8211; Bundle</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-reviews/" rel="nofollow ugc">wpDiscuz &#8211; Reviews</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-emoticons/" rel="nofollow ugc">wpDiscuz &#8211; Emoticons</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-user-notifications/" rel="nofollow ugc">wpDiscuz &#8211; User Notifications</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-media-uploader/" rel="nofollow ugc">wpDiscuz &#8211; Media Uploader</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-embeds/" rel="nofollow ugc">wpDiscuz &#8211; Embeds</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-comment-author-info/" rel="nofollow ugc">wpDiscuz &#8211; Comment Author Info</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-recaptcha/" rel="nofollow ugc">wpDiscuz &#8211; Google ReCaptcha</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-mycred/" rel="nofollow ugc">wpDiscuz &#8211; myCRED Integration</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-widgets/" rel="nofollow ugc">wpDiscuz &#8211; Widgets</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-frontend-moderation/" rel="nofollow ugc">wpDiscuz &#8211; Front-end Moderation</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-subscribe-manager/" rel="nofollow ugc">wpDiscuz &#8211; Subscription Manager</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-comment-search/" rel="nofollow ugc">wpDiscuz &#8211; Comment Search</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-report-flagging/" rel="nofollow ugc">wpDiscuz &#8211; Comment Report and Flagging</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-ads-manager/" rel="nofollow ugc">wpDiscuz &#8211; Ads Manager</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-user-comment-mentioning/" rel="nofollow ugc">wpDiscuz &#8211; User &amp; Comment Mentioning</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-advanced-likers/" rel="nofollow ugc">wpDiscuz &#8211; Advanced Likers</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-online-users/" rel="nofollow ugc">wpDiscuz &#8211; Online Users</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-private-comments/" rel="nofollow ugc">wpDiscuz &#8211; Private Comments</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-syntax-highlighter/" rel="nofollow ugc">wpDiscuz &#8211; Syntax Highlighter</a></li> <li>| <a href="https://gvectors.com/product/comments-censure-pro/" rel="nofollow ugc">Comments Censure PRO</a></li> </ul> <h4>Integration Add-ons</h4> <ul> <li>| <a href="https://gvectors.com/product/wpdiscuz-buddypress-integration/" rel="nofollow ugc">wpDiscuz &#8211; BuddyPress Integration</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-giphy-integration/" rel="nofollow ugc">wpDiscuz &#8211; GIPHY Integration</a></li> <li>| <a href="https://gvectors.com/product/wpdiscuz-voice-commenting/" rel="nofollow ugc">wpDiscuz &#8211; Voice Commenting</a></li> </ul>
WordPress Plugin DirectoryWordPress Plugin Directory
4.6M