What the vulnerability does
01Description
Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11).
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11).
Explanation of Vulnerability in Simple Terms
The wpDiscuz plugin for WordPress versions up to 7.3.11 exposes sensitive information through improper access controls. An attacker can retrieve private comment data and user information without authentication, though the attack requires specific conditions to succeed. Site administrators should update to a version newer than 7.3.11 to prevent unauthorized information disclosure.
What an attacker can do
Read private comments and user data without logging in.
Potential impact on your site
Private comments and user information may be exposed to unauthenticated visitors.
Conditions required to exploit
Network access to the site; attack complexity is high, suggesting specific conditions must be met.
Key dates
External resources
Related vulnerabilities