plugin

Wp Recentcomments Vulnerabilities

8 known security issues reported for the Wp Recentcomments WordPress plugin. Most recent disclosed Dec 9, 2024.

1 critical 2 medium

Running Wp Recentcomments on your site? Check whether your installed version is affected.

Scan your site free

WP-RecentComments [wp-recentcomments] <= 2.2.7 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in mg12 WP-RecentComments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-RecentComments: from n/a through 2.2.7.

Affected:
up to 2.2.7
Fix:
No patched version reported
Disclosed:
Dec 9, 2024

CVE-2023-23886 on NVD →

WP-RecentComments [wp-recentcomments] <= 2.2.7 (unfixed + closed)

unknown

No patched version available. WordFence discovered and reported this Sensitive Data Exposure vulnerability in WordPress WP-RecentComments Plugin. This vulnerability has not been known to be fixed yet.

Affected:
up to 2.2.7
Fix:
No patched version reported
Disclosed:
Feb 23, 2023

WP-RecentComments <= 2.2.7 - Unauthenticated Information Exposure

medium

The WP-RecentComments plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.2.7. This can allow unauthenticated attackers to extract sensitive data including comments on posts even if the posts themselves are not visible to the user. The plugin uses the `init` hook for...

CVSS:
5.3
Affected:
up to 2.2.7
Fix:
No patched version reported
Disclosed:
Feb 22, 2023

CVE-2023-23886 on NVD →

WP-RecentComments [wp-recentcomments] <= 2.2.7 (unfixed + closed)

unknown

The WP-RecentComments plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.2.7. This can allow unauthenticated attackers to extract sensitive data including comments on posts even if the posts themselves are not visible to the user. The plugin uses the `init` hook for...

Affected:
up to 2.2.7
Fix:
No patched version reported
Disclosed:
Feb 22, 2023

WP-RecentComments [wp-recentcomments] <= 2.0.7 (closed)

unknown

[en] SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Feb 14, 2012

CVE-2012-1067 on NVD →

WP-RecentComments [wp-recentcomments] < 2.0.7 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Feb 14, 2012

CVE-2012-1068 on NVD →

WP-RecentComments <= 2.0.7 - SQL Injection

critical

SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS:
9.8
Affected:
up to 2.0.7
Fixed in:
2.1
Disclosed:
Sep 22, 2011

CVE-2012-1067 on NVD →

WP-RecentComments <= 2.0.6 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.

CVSS:
6.1
Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Sep 22, 2011

CVE-2012-1068 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database