CVE-2022-43492 MEDIUM

CVE-2022-43492: WordPress Comments – wpDiscuz plugin 7.4.2 - Auth. Insecure Direct Object References (IDOR) vulnerability

Vendor Gvectors Team
Product Comments – wpDiscuz (WordPress plugin)
Published November 18, 2022
Last update April 28, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.

Explanation of Vulnerability in Simple Terms

02Summary

The wpDiscuz plugin for WordPress contains an information disclosure vulnerability in versions 7.4.2 and earlier. An authenticated user with low privileges can read sensitive data they should not have access to. The vulnerability requires network access but no user interaction. Site administrators should update to a version newer than 7.4.2 to remediate the issue.

What an attacker can do

03Attacker Capabilities

Read sensitive data accessible only to higher-privileged users.

Potential impact on your site

04Site Impact

Unauthorized users can view private comments, user data, or other restricted information stored by the plugin.

Conditions required to exploit

05Prerequisites

Attacker must be logged in with a low-privilege account (e.g., subscriber or commenter).

Key dates

06Disclosure timeline

November 18, 2022 CVE published
April 28, 2026 Record updated