Vulnerabilities > Gvectors > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-10-25 CVE-2024-9488 Unspecified vulnerability in Gvectors Wpdiscuz
The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24.
network
low complexity
gvectors
critical
9.8
2020-08-24 CVE-2020-24186 Unrestricted Upload of File with Dangerous Type vulnerability in Gvectors Wpdiscuz
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
network
low complexity
gvectors CWE-434
critical
10.0
2020-06-18 CVE-2020-13640 SQL Injection vulnerability in Gvectors Wpdiscuz
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request.
network
low complexity
gvectors CWE-89
critical
9.8
2019-06-19 CVE-2018-16613 Unspecified vulnerability in Gvectors Wpforo Forum
An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress.
network
low complexity
gvectors
critical
9.8
2018-05-28 CVE-2018-11515 SQL Injection vulnerability in Gvectors Wpforo
The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.
network
low complexity
gvectors CWE-89
critical
9.8