Comments – wpDiscuz, CVE-2020-13640
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jun 18, 2020
- Research Description
- A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)
- Affected versions
-
Min -, max 4.0.0.
- Status
-
vulnerable