CVE Vulnerabilities

CVE-2025-13820

Published: Jan 01, 2026 | Modified: Jan 05, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Comments WordPress plugin before 7.6.40 does not properly validate users identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.

References