CVE 5.3 MEDIUM

Comments – wpDiscuz < 7.6.40 - Unauthenticated Account Takeover_CVE-2025-13820

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.

Basic Information

ID CVE-2025-13820
Source WPScan
Published Jan 1, 2026 at 06:00
Modified Jan 5, 2026 at 19:57

Affected Product

Vendor Unknown
Product Comments
Affected Versions Unknown Comments 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.