What the vulnerability does
01Description
Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.
Explanation of Vulnerability in Simple Terms
The wpDiscuz plugin for WordPress contains an information disclosure vulnerability in versions 7.4.2 and earlier. An authenticated user with low privileges can read sensitive data they should not have access to. The vulnerability requires network access but no user interaction. Site administrators should update to a version newer than 7.4.2 to remediate the issue.
What an attacker can do
Read sensitive data accessible only to higher-privileged users.
Potential impact on your site
Unauthorized users can view private comments, user data, or other restricted information stored by the plugin.
Conditions required to exploit
Attacker must be logged in with a low-privilege account (e.g., subscriber or commenter).
Key dates
External resources