plugin

Disqus Comment System Vulnerabilities

5 known security issues reported for the Disqus Comment System WordPress plugin. Most recent disclosed Sep 17, 2014.

1 critical 1 high 3 medium

Running Disqus Comment System on your site? Check whether your installed version is affected.

Scan your site free

Disqus Comment System < 2.79 - Multiple Cross-Site Request Forgery

medium

Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.79 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) activate or (2) deactivate the plugin via the active parameter to wp-admin/edit-comments.php, (3) import co...

CVSS:
6.3
Affected:
up to 2.79
Fixed in:
2.79
Disclosed:
Sep 17, 2014

CVE-2014-5346 on NVD →

Disqus Comment System < 2.76 - Cross-Site Request Forgery

medium

Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) disqus_replace, (2) disqus_public_key, or (3) disqus_sec...

CVSS:
5.4
Affected:
up to 2.76
Fixed in:
2.76
Disclosed:
Aug 12, 2014

CVE-2014-5347 on NVD →

Disqus Comment System < 2.76 - Remote Code Execution

critical

The Disqus Comment System plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.75 via the 'getNextToken()' function that parsed user supplied data through the eval() function. This allows unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 2.76
Fixed in:
2.76
Disclosed:
Jun 20, 2014

Disqus Comment System < 2.76 - Reflected Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.

CVSS:
6.1
Affected:
up to 2.76
Fixed in:
2.76
Disclosed:
Jun 9, 2014

CVE-2014-5345 on NVD →

Disqus Comment System < 2.68 - Reflected Cross-Site Scripting

high

The Disqus Comment System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the User-Agent HTTP Header in versions before 2.68 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...

CVSS:
7.1
Affected:
up to 2.68
Fixed in:
2.68
Disclosed:
Dec 11, 2011

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database