CVE Alert: CVE-2026-22202 - gVectors - wpDiscuz - RedPacket Security

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by

RedPacket Security
CVE Alert: CVE-2026-22193 - gVectors - wpDiscuz - RedPacket Security

wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escaping in SQL

RedPacket Security
CVE Alert: CVE-2026-22182 - gVectors - wpDiscuz - RedPacket Security

wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by

RedPacket Security

Der @schelmo fragte nach "Insights", hier sind sie:

Wir haben das Like-Plugin für Kommentare getauscht und dabei die Likes von wpdiscuz in der Datenbank migriert. Ungetestet direkt in #prod because #norisknofun!

Dabei hat #wordpress versucht sich 4GiB RAM zu snacken. Da sagt php-fpm natürlich "Nö is nich, geh weg!".

#wpDiscuz kann auch Mailbenachrichtigungen, die hat laut Umfrage aber fast keiner genutzt. Diese Funktion ist ersatzlos gestrichen.

Ditching Disqus: Why I Chose wpDiscuz for My Linux Blog

After migrating my website from Blogger, I initially tried using WordPress’s native comment system, but I simply couldn’t stick with it—it lacks features and offers a limited experience. I considered Disqus’s paid plan, but after reviewing how it handles user data, I decided to seriously look for open source alternatives. That’s what led me to wpDiscuz.

https://www.linuxtechmore.com/why-i-ditched-disqus-for-wpdiscuz

#OpenSource #Privacy #Disqus #wpDiscuz #WordPress

Zehntausende WordPress-Websites mit dem Plugin wpDiscuz könnten Schadcode auf Web-Server lassen.
Kritische Lücke mit Höchstwertung in WordPress-Plugin wpDiscuz
#Patchday #Sicherheitslücken #Update #Website #Wordpress #wpDiscuz
Kritische Lücke mit Höchstwertung in WordPress-Plugin wpDiscuz

Zehntausende WordPress-Websites mit dem Plugin wpDiscuz könnten Schadcode auf Web-Server lassen.

Thousands of websites at risk from critical WordPress commenting plugin vulnerability - A critical vulnerability in a third-party comments plugin installed on over 70,000 websites runnin... more: https://hotforsecurity.bitdefender.com/blog/thousands-of-websites-at-risk-from-critical-wordpress-plugin-vulnerability-23844.html#new_tab #vulnerability #guestblog #wordpress #wpdiscuz
Thousands of websites at risk from critical WordPress plugin...

A critical vulnerability in a third-party plugin installed on over 70,000 websites running WordPress could allow hackers to execute malicious code remotely. The vulnerability, discovered by security researchers at Wordfence, hides... #vulnerabilitydisclosure #vulnerabilityexploit #wordpressexploit

HOTforSecurity
Critical Wordpress plugin bug lets hackers take over hosting account

Hackers can exploit a maximum severity vulnerability in the wpDiscuz plugin installed on over 70,000 WordPress sites to execute code remotely after uploading arbitrary files on servers hosting vulnerable sites.

Critical #Wordpress plugin bug lets hackers take over hosting account.
Hackers can exploit a maximum severity #vulnerability in the #wpDiscuz #plugin installed on over 70,000 #WordPress sites to execute code remotely after uploading arbitrary files on servers hosting vulnerable sites.
https://www.bleepingcomputer.com/news/security/critical-wordpress-plugin-bug-lets-hackers-take-over-hosting-account/?&web_view=true
#security #vulnerabilities #website
Critical Wordpress plugin bug lets hackers take over hosting account

Hackers can exploit a maximum severity vulnerability in the wpDiscuz plugin installed on over 70,000 WordPress sites to execute code remotely after uploading arbitrary files on servers hosting vulnerable sites.