A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGvectors Wpdiscuz
APPGvectors≤ 5.3.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References
Related vulnerabilities
CVE-2026-22193CRITICAL9.2PL ✓same product
SQL Injection w wtyczce WordPress wpDiscuz (getAllSubscriptions)
CVE-2024-9488CRITICAL9.8PL ✓same product
Authentication bypass w pluginie wpDiscuz dla WordPress (do wersji 7.6.24)
CVE-2020-24186CRITICAL10.0PL ✓same product
RCE poprzez nieautoryzowany upload plików PHP w wtyczce WordPress wpDiscuz
CVE-2026-22192HIGH8.8same product
Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthent...
CVE-2026-22182HIGH8.7same product
wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users...