HyperComments <= 1.2.2 - Unauthenticated (Subscriber+) Arbitrary Options Update
high
The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the hc_request_handler function in all versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to update arbitrary optio...
- CVSS:
- 8.8
- Affected:
- up to 1.2.2
- Fix:
- No patched version reported
- Disclosed:
- Jun 4, 2025
CVE-2025-5701 on NVD →
HyperComments <= 1.2.2 - Arbitrary File Deletion
high
The HyperComments plugin for WordPress is vulnerable to Arbitrary File Deletion via the 'xml' GET parameter in versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to delete files on the vulnerable filesystem.
- CVSS:
- 7.2
- Affected:
- up to 1.2.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 7, 2020
HyperComments [hypercomments] < 1.2.3 (unfixed + closed)
unknown
Unauthenticated Arbitrary File Deletion vulnerability found by Lenon Leite in WordPress HyperComments plugin (versions <= 1.2.2).
- Affected:
- up to 1.2.3
- Fix:
- No patched version reported
- Disclosed:
- Oct 7, 2020
HyperComments [hypercomments] <= 1.2.2 (unfixed + closed)
unknown
The HyperComments plugin for WordPress is vulnerable to Arbitrary File Deletion via the 'xml' GET parameter in versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to delete files on the vulnerable filesystem.
- Affected:
- up to 1.2.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 7, 2020
HyperComments [hypercomments] <= 1.2.2 (unfixed + closed)
unknown
The plugin does not validate and sanitise user input which is being concatenated to create a file path, passed to unlink(), which leads to an arbitrary file deletion issue.
For more details about this issue, please see the reference.
- Affected:
- up to 1.2.2
- Fix:
- No patched version reported
HyperComments [hypercomments] <= 1.2.2 (unfixed)
unknown
- Affected:
- up to 1.2.2
- Fix:
- No patched version reported
CVE-2025-5701 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database