HomeDefault status
unaffected
Any version before 7.6.40
affected
Description
The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.
Problem types
CWE-269 Improper Privilege Management
Product status
Any version before 7.6.40
Credits
wcraft
WPScan
References
wpscan.com/...rability/21bc9b41-a967-42dc-9916-bb993b05709c/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.