CVE-2025-13820

The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provider, allowing an attacker to log in to any user (when knowing their email address) when such user does not have an account on disqus.com yet.
Configurations

No configuration.

History

No history.

Information

Published : 2026-01-01 06:15

Updated : 2026-06-17 08:34


NVD link : CVE-2025-13820

Mitre link : CVE-2025-13820

CVE.ORG link : CVE-2025-13820


JSON object : View

Products Affected

No product.

CWE

No CWE.