What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a through 7.6.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments – wpDiscuz.This issue affects Comments – wpDiscuz: from n/a through 7.6.3.
Explanation of Vulnerability in Simple Terms
wpDiscuz versions up to 7.6.3 contain a vulnerability that allows high-privilege users to cause a denial of service by disrupting site availability. The flaw requires administrator-level access and does not affect data confidentiality or integrity. A patch version has not been publicly identified.
What an attacker can do
An administrator can disrupt site availability temporarily.
Potential impact on your site
Site administrators with malicious intent could temporarily degrade site performance or availability.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities