CVE-2022-23984 LOW

CVE-2022-23984: WordPress wpDiscuz plugin <= 7.3.11 - Sensitive Information Disclosure

Vendor Gvectors Team
Product Comments – wpDiscuz (WordPress plugin)
Weakness CWE-200 · Info exposure
Published February 21, 2022
Last update April 28, 2026

CVSS base score

3.7/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11).

Explanation of Vulnerability in Simple Terms

02Summary

The wpDiscuz plugin for WordPress versions up to 7.3.11 exposes sensitive information through improper access controls. An attacker can retrieve private comment data and user information without authentication, though the attack requires specific conditions to succeed. Site administrators should update to a version newer than 7.3.11 to prevent unauthorized information disclosure.

What an attacker can do

03Attacker Capabilities

Read private comments and user data without logging in.

Potential impact on your site

04Site Impact

Private comments and user information may be exposed to unauthenticated visitors.

Conditions required to exploit

05Prerequisites

Network access to the site; attack complexity is high, suggesting specific conditions must be met.

Key dates

06Disclosure timeline

February 21, 2022 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE