
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13820 is an unauthenticated account takeover vulnerability in the Comments – wpDiscuz WordPress plugin affecting versions before 7.6.40. The flaw allows an attacker to log in as any WordPress user — including administrators — by knowing only their email address, provided that user has not yet registered on disqus.com. It was publicly disclosed on December 11, 2025, and reported to NVD on January 1, 2026. WPScan assigns a CVSS score of 8.1 (High), while CISA-ADP rates it 5.3 (Medium) (WPScan).
The root cause is improper privilege management (CWE-269) in the plugin's Disqus social login integration, classified under OWASP A2: Broken Authentication and Session Management. When a user authenticates via the Disqus provider, the plugin matches the Disqus account's email address to a WordPress user account without verifying that the Disqus account was legitimately created by that user. An attacker can exploit this by creating a Disqus account using a victim's email address (e.g., the site administrator's), then using the "Connect with D" login option on any page embedding the wpDiscuz widget to be authenticated directly as that WordPress user. Exploitation requires no prior authentication and a working proof-of-concept with a demonstration video is publicly available (WPScan).
Successful exploitation grants an attacker full access to the targeted WordPress user's account, including administrator-level access if the victim's email is known. This can lead to complete site compromise — including content modification, installation of malicious plugins or backdoors, credential harvesting, and lateral movement within the hosting environment. The attack is unauthenticated and requires no interaction from the victim, making it particularly dangerous for sites with publicly known administrator email addresses (WPScan).
A verified proof-of-concept is publicly available, including a demonstration video linked from the WPScan advisory, making this vulnerability easily weaponizable by low-skilled attackers. The EPSS score is 0.017% (0.000170), suggesting low automated exploitation activity at the time of scoring. No CISA KEV catalog listing or confirmed in-the-wild exploitation campaigns have been reported. The attack requires specific preconditions: the Disqus login provider must be enabled and configured, the wpDiscuz widget must be embedded on a post/page, and the target user must not already have a Disqus account (WPScan).
disqus.com using the target user's email address (exploiting the fact that the victim has not yet registered on Disqus).wpdiscuz or disqus as the login method) from unfamiliar IP addresses or at unusual times; sudden administrator-level actions (plugin installs, user creation) shortly after a Disqus-authenticated session.Update the Comments – wpDiscuz plugin to version 7.6.40 or later, which contains the fix for this vulnerability. As an interim workaround, disable the Disqus social login provider in the plugin settings (/wp-admin/admin.php?page=wpdiscuz_options_page&wpd_tab=social) until the update can be applied. Site administrators should also audit recent logins via the Disqus provider for any suspicious activity and review administrator account integrity (WPScan).
The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for December 8–14, 2025, and included in Sucuri's January 2026 vulnerability patch roundup, indicating broad awareness within the WordPress security community. The WPScan advisory was verified by the WPScan team and includes a researcher-submitted proof-of-concept with a public demonstration video, lending credibility to the severity assessment (Wordfence Blog, Sucuri Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."