CVE-2025-13820: Comments – wpDiscuz < 7.6.40 - Unauthenticated Account Takeover
The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13820?
CVE-2025-13820 has a high severity rating due to its potential for unauthorized user access.
How do I fix CVE-2025-13820?
To fix CVE-2025-13820, update the Comments WordPress plugin to version 7.6.40 or later.
Who is affected by CVE-2025-13820?
Users of the Comments WordPress plugin prior to version 7.6.40 are affected by CVE-2025-13820.
What does CVE-2025-13820 exploit?
CVE-2025-13820 exploits improper user identity validation when using the disqus.com provider.
Can CVE-2025-13820 allow attackers to access any user account?
Yes, CVE-2025-13820 allows attackers to log in to any user account with just the user's email if they do not have a disqus.com account.