• About Us
  • Contact Us
  • Advertise
  • Privacy Policy
  • Guest Post
No Result
View All Result
Digital Phablet
  • Home
  • NewsLatest
  • Technology
    • Education Tech
    • Home Tech
    • Office Tech
    • Fintech
    • Digital Marketing
  • Social Media
  • Gaming
  • Smartphones
  • AI
  • Reviews
  • Interesting
  • How To
  • Home
  • NewsLatest
  • Technology
    • Education Tech
    • Home Tech
    • Office Tech
    • Fintech
    • Digital Marketing
  • Social Media
  • Gaming
  • Smartphones
  • AI
  • Reviews
  • Interesting
  • How To
No Result
View All Result
Digital Phablet
No Result
View All Result

Home » wpDiscuz WordPress Plugin Puts Thousands of Websites at Risk

wpDiscuz WordPress Plugin Puts Thousands of Websites at Risk

DP Staff by DP Staff
July 30, 2020
in Technology
Reading Time: 1 min read
A A
ADVERTISEMENT

Select Language:

A security flow found in the wpDiscuz’s WordPress plugin which can allow hackers to inject malicious code easily on any website.

ADVERTISEMENT

This vulnerability was first identified by security experts at Wordfence, who further confirms that with this flaw, hackers will also be able to execute PHP files and upload arbitrary files to the website where this plugin is installed.

wpDiscuz provides an alternative to the commenting system to WordPress, just like jetpack comments, Disqus, or any other famous commenting plugin.

This security flaw was first identified by Wordfence and had asked wpDiscuz to fix it, for that after a few days, the devs said they had fixed it. But later, in the latest update of the WordPress plugin, this issue was once again found to which wordfence took notice and told, the patch was unable to fix the security flaw as of now.

ADVERTISEMENT

The issue was found in version 7 of the WordPress plugin, in the feature which allows users to upload images to the comments. The system is unable to detect if the file extension is of an image or malicious code.

As of now the best thing for the web developers who are using wpDiscuz is to move away from it if the plugin is not getting a patch within 24 hours, keeping the plugin would allow hackers to hack your sites and all the other sites associated with that host to be at the risk of hacking.

ChatGPT ChatGPT Perplexity AI Perplexity Gemini AI Logo Gemini AI Grok AI Logo Grok AI
Google Banner
Tags: PrivacyWordpress
ADVERTISEMENT
DP Staff

DP Staff

Related Posts

India drops plan to preload cybersecurity app after public backlash
News

India drops plan to preload cybersecurity app after public backlash

December 3, 2025
Amazon Ring Cameras Now Scan Faces Creeping Me Out.jpg
Home Tech

Amazon Ring Cameras Now Scan Faces Creeping Me Out

October 10, 2025
Apple eliminates ICE tracking apps following Trump administration pressure
News

Apple eliminates ICE tracking apps following Trump administration pressure

October 3, 2025
Technology

From Brainy Bandages to New Teeth: Google’s $425M Challenge

September 12, 2025
Next Post

Use Mac OS Emulator on Your Windows PC, Best Way To Run Mac on PC

  • About Us
  • Contact Us
  • Advertise
  • Privacy Policy
  • Guest Post

© 2025 Digital Phablet

No Result
View All Result
  • Home
  • News
  • Technology
    • Education Tech
    • Home Tech
    • Office Tech
    • Fintech
    • Digital Marketing
  • Social Media
  • Gaming
  • Smartphones

© 2025 Digital Phablet