
CVE-2025-4224 – wpForo + wpForo Advanced Attachments <= 3.1.3 - Unauthenticated Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2025-4224
02 Jun 2025 — The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upload names in all versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://gvectors.com/product/wpforo-advanced-attachments/#tab-changelog • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-35681 – WordPress wpDiscuz plugin <= 7.6.18 - Cross Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2024-35681
06 Jun 2024 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in gVectors Team wpDiscuz allows Stored XSS.This issue affects wpDiscuz: from n/a through 7.6.18. La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web (XSS o 'Cross-site Scripting') en gVectors Team wpDiscuz permite XSS Almacenado. Este problema afecta a wpDiscuz: desde n/a hasta 7.6.18. The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cro... • https://patchstack.com/database/vulnerability/wpdiscuz/wordpress-wpdiscuz-plugin-7-6-18-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-49759 – WordPress WooDiscuz – WooCommerce Comments Plugin <= 2.3.0 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2023-49759
04 Dec 2023 — Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0. Vulnerabilidad de Cross-Site Request Forgery (CSRF) engVectors Team WooDiscuz – WooCommerce Comments. Este problema afecta a WooDiscuz – WooCommerce Comments: desde n/a hasta 2.3.0. The WooDiscuz – WooCommerce Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.0. This is due ... • https://patchstack.com/database/vulnerability/woodiscuz-woocommerce-comments/wordpress-woodiscuz-woocommerce-comments-plugin-2-3-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2023-47872 – WordPress wpForo Forum Plugin <= 2.2.3 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-47872
20 Nov 2023 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team wpForo Forum allows Stored XSS.This issue affects wpForo Forum: from n/a through 2.2.3. Vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('Cross-site Scripting') en gVectors Team wpForo Forum permite almacenar XSS. Este problema afecta a wpForo Forum: desde n/a hasta 2.2.3. The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Sc... • https://patchstack.com/database/vulnerability/wpforo/wordpress-wpforo-plugin-2-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-47870 – WordPress wpForo Forum Plugin <= 2.2.6 is vulnerable to Broken Access Control and Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2023-47870
20 Nov 2023 — Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a through 2.2.6. Cross-Site Request Forgery (CSRF), vulnerabilidad de autorización faltante en gVectors Team wpForo Forum wpforo permite Cross-Site Request Forgery, funcionalidad de acceso no restringida adecuadamente por las ACL, lo qu... • https://patchstack.com/database/vulnerability/wpforo/wordpress-wpforo-plugin-2-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) CWE-862: Missing Authorization •

CVE-2023-51691 – WordPress wpDiscuz Plugin <= 7.6.12 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-51691
17 Nov 2023 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team Comments – wpDiscuz allows Stored XSS.This issue affects Comments – wpDiscuz: from n/a through 7.6.12. La vulnerabilidad de neutralización incorrecta de la entrada durante de generación de páginas web ('cross-site Scripting') en gVectors Team Comments – wpDiscuz permite XSS almacenado. Este problema afecta a Comments – wpDiscuz: desde n/a hasta 7.6.12. The Comments – wpDiscuz plugin for WordPr... • https://patchstack.com/database/vulnerability/wpdiscuz/wordpress-wpdiscuz-plugin-7-6-12-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-47775 – WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2023-47775
14 Nov 2023 — Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en el complemento gVectors Team Comments — wpDiscuz en versiones <= 7.6.11. The wpDiscuz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.6.11. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to dismiss admin n... • https://patchstack.com/database/vulnerability/wpdiscuz/wordpress-wpdiscuz-plugin-7-6-11-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2023-47185 – WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-47185
31 Oct 2023 — Unauth. Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions. Vulnerabilidad de Cross-Site Scripting (XSS) Almacenada No Autenticada en engVectors Team Comments en el complemento wpDiscuz en versiones <= 7.6.11. The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the filename of an image uploaded in a comment submission in all versions up to, and including, 7.6.11 due to insufficient input sanitization and... • https://patchstack.com/database/vulnerability/wpdiscuz/wordpress-wpdiscuz-plugin-7-6-11-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-46311 – WordPress wpDiscuz Plugin <= 7.6.3 is vulnerable to Insecure Direct Object References (IDOR)
https://notcve.org/view.php?id=CVE-2023-46311
22 Oct 2023 — Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a through 7.6.3. Vulnerabilidad de omisión de autorización a través de clave controlada por el usuario en gVectors Team Comments – wpDiscuz. Este problema afecta a Comments – wpDiscuz: desde n/a hasta 7.6.3. The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on an unknown function in versions ... • https://patchstack.com/database/vulnerability/wpdiscuz/wordpress-wpdiscuz-plugin-7-6-3-insecure-direct-object-references-idor-vulnerability?_s_id=cve • CWE-639: Authorization Bypass Through User-Controlled Key •

CVE-2023-3998 – wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Post Rating Increase/Decrease
https://notcve.org/view.php?id=CVE-2023-3998
12 Sep 2023 — The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization check on the userRate function in versions up to, and including, 7.6.3. This makes it possible for unauthenticated attackers to increase or decrease the rating of a post. El complemento wpDiscuz para WordPress es vulnerable a modificaciones no autorizadas de datos debido a una falta de verificación de autorización en la función userRate en versiones hasta la 7.6.3 incluida. Esto hace posible q... • https://plugins.trac.wordpress.org/browser/wpdiscuz/trunk/utils/class.WpdiscuzHelperAjax.php#L886 • CWE-639: Authorization Bypass Through User-Controlled Key CWE-862: Missing Authorization •