Disqus Comment System < 2.79 - Multiple Cross-Site Request Forgery
medium
Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.79 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) activate or (2) deactivate the plugin via the active parameter to wp-admin/edit-comments.php, (3) import co...
- CVSS:
- 6.3
- Affected:
- up to 2.79
- Fixed in:
- 2.79
- Disclosed:
- Sep 17, 2014
CVE-2014-5346 on NVD →
Disqus Comment System < 2.76 - Cross-Site Request Forgery
medium
Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) disqus_replace, (2) disqus_public_key, or (3) disqus_sec...
- CVSS:
- 5.4
- Affected:
- up to 2.76
- Fixed in:
- 2.76
- Disclosed:
- Aug 12, 2014
CVE-2014-5347 on NVD →
Disqus Comment System < 2.76 - Remote Code Execution
critical
The Disqus Comment System plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.75 via the 'getNextToken()' function that parsed user supplied data through the eval() function. This allows unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 2.76
- Fixed in:
- 2.76
- Disclosed:
- Jun 20, 2014
Disqus Comment System < 2.76 - Reflected Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.
- CVSS:
- 6.1
- Affected:
- up to 2.76
- Fixed in:
- 2.76
- Disclosed:
- Jun 9, 2014
CVE-2014-5345 on NVD →
Disqus Comment System < 2.68 - Reflected Cross-Site Scripting
high
The Disqus Comment System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the User-Agent HTTP Header in versions before 2.68 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if...
- CVSS:
- 7.1
- Affected:
- up to 2.68
- Fixed in:
- 2.68
- Disclosed:
- Dec 11, 2011
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database