CVE-2024-6704: Comments – wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection
The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of filtering of HTML tags in comments. This makes it possible for unauthenticated attackers to add HTML such as hyperlinks to comments when rich editing is disabled.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6704?
CVE-2024-6704 has a medium severity level due to its potential for allowing HTML injection.
How does CVE-2024-6704 affect WordPress sites?
CVE-2024-6704 affects WordPress sites using the wpDiscuz plugin versions up to and including 7.6.21 by allowing unauthenticated attackers to inject HTML into comments.
How do I fix CVE-2024-6704?
To fix CVE-2024-6704, update the wpDiscuz plugin to a version higher than 7.6.21 that includes the necessary security patches.
Who is vulnerable to CVE-2024-6704?
Any WordPress site using the wpDiscuz plugin version 7.6.21 or earlier is vulnerable to CVE-2024-6704.
What type of vulnerability is CVE-2024-6704?
CVE-2024-6704 is classified as an HTML Injection vulnerability due to inadequate filtering of HTML tags in user comments.