PT-2024-37811 · WordPress · Wpdiscuz

Tieu Pham Trong Nhan

·

Published

2024-08-02

·

Updated

2025-06-05

·

CVE-2024-6704

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Comments – wpDiscuz plugin for WordPress versions prior to 7.6.22
Description The issue is related to HTML Injection due to a lack of filtering of HTML tags in comments. This allows unauthenticated attackers to add HTML, such as hyperlinks, to comments when rich editing is disabled.
Recommendations For versions prior to 7.6.22, update to version 7.6.22 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-6704

Affected Products

Wpdiscuz