WP-RecentComments [wp-recentcomments] <= 2.2.7 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in mg12 WP-RecentComments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-RecentComments: from n/a through 2.2.7.
- Affected:
- up to 2.2.7
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2024
CVE-2023-23886 on NVD →
WP-RecentComments [wp-recentcomments] <= 2.2.7 (unfixed + closed)
unknown
No patched version available.
WordFence discovered and reported this Sensitive Data Exposure vulnerability in WordPress WP-RecentComments Plugin. This vulnerability has not been known to be fixed yet.
- Affected:
- up to 2.2.7
- Fix:
- No patched version reported
- Disclosed:
- Feb 23, 2023
WP-RecentComments <= 2.2.7 - Unauthenticated Information Exposure
medium
The WP-RecentComments plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.2.7. This can allow unauthenticated attackers to extract sensitive data including comments on posts even if the posts themselves are not visible to the user. The plugin uses the `init` hook for...
- CVSS:
- 5.3
- Affected:
- up to 2.2.7
- Fix:
- No patched version reported
- Disclosed:
- Feb 22, 2023
CVE-2023-23886 on NVD →
WP-RecentComments [wp-recentcomments] <= 2.2.7 (unfixed + closed)
unknown
The WP-RecentComments plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.2.7. This can allow unauthenticated attackers to extract sensitive data including comments on posts even if the posts themselves are not visible to the user. The plugin uses the `init` hook for...
- Affected:
- up to 2.2.7
- Fix:
- No patched version reported
- Disclosed:
- Feb 22, 2023
WP-RecentComments [wp-recentcomments] <= 2.0.7 (closed)
unknown
[en] SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Feb 14, 2012
CVE-2012-1067 on NVD →
WP-RecentComments [wp-recentcomments] < 2.0.7 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Feb 14, 2012
CVE-2012-1068 on NVD →
WP-RecentComments <= 2.0.7 - SQL Injection
critical
SQL injection vulnerability in the WP-RecentComments plugin 2.0.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in an rc-content action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
- CVSS:
- 9.8
- Affected:
- up to 2.0.7
- Fixed in:
- 2.1
- Disclosed:
- Sep 22, 2011
CVE-2012-1067 on NVD →
WP-RecentComments <= 2.0.6 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the rc_ajax function in core.php in the WP-RecentComments plugin before 2.0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter, related to AJAX paging.
- CVSS:
- 6.1
- Affected:
- up to 2.0.7
- Fixed in:
- 2.0.7
- Disclosed:
- Sep 22, 2011
CVE-2012-1068 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database