CVE-2025-13820: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13820 is an unauthenticated account takeover vulnerability in the Comments – wpDiscuz WordPress plugin affecting versions before 7.6.40. The flaw allows an attacker to log in as any WordPress user — including administrators — by knowing only their email address, provided that user has not yet registered on disqus.com. It was publicly disclosed on December 11, 2025, and reported to NVD on January 1, 2026. WPScan assigns a CVSS score of 8.1 (High), while CISA-ADP rates it 5.3 (Medium) (WPScan).

Technical details

The root cause is improper privilege management (CWE-269) in the plugin's Disqus social login integration, classified under OWASP A2: Broken Authentication and Session Management. When a user authenticates via the Disqus provider, the plugin matches the Disqus account's email address to a WordPress user account without verifying that the Disqus account was legitimately created by that user. An attacker can exploit this by creating a Disqus account using a victim's email address (e.g., the site administrator's), then using the "Connect with D" login option on any page embedding the wpDiscuz widget to be authenticated directly as that WordPress user. Exploitation requires no prior authentication and a working proof-of-concept with a demonstration video is publicly available (WPScan).

Impact

Successful exploitation grants an attacker full access to the targeted WordPress user's account, including administrator-level access if the victim's email is known. This can lead to complete site compromise — including content modification, installation of malicious plugins or backdoors, credential harvesting, and lateral movement within the hosting environment. The attack is unauthenticated and requires no interaction from the victim, making it particularly dangerous for sites with publicly known administrator email addresses (WPScan).

Exploitability

A verified proof-of-concept is publicly available, including a demonstration video linked from the WPScan advisory, making this vulnerability easily weaponizable by low-skilled attackers. The EPSS score is 0.017% (0.000170), suggesting low automated exploitation activity at the time of scoring. No CISA KEV catalog listing or confirmed in-the-wild exploitation campaigns have been reported. The attack requires specific preconditions: the Disqus login provider must be enabled and configured, the wpDiscuz widget must be embedded on a post/page, and the target user must not already have a Disqus account (WPScan).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Comments – wpDiscuz plugin (versions before 7.6.40) with the Disqus social login provider enabled. Check for the "Connect with D" login button on comment sections of posts or pages.
  2. Obtain target email: Determine the email address of the target WordPress user (e.g., administrator). This may be found via public WHOIS records, the site's contact page, or other OSINT methods.
  3. Create Disqus account: In an incognito/private browser session, register a new account on disqus.com using the target user's email address (exploiting the fact that the victim has not yet registered on Disqus).
  4. Trigger social login: Navigate to any post or page on the target WordPress site that has the wpDiscuz comment widget embedded, and click the "Connect with D" (Disqus) login option.
  5. Achieve account takeover: The plugin matches the Disqus account's email to the existing WordPress user without further verification, authenticating the attacker directly as the target user (e.g., site administrator), granting full account access (WPScan).

Indicators of compromise

  • Logs: WordPress authentication logs showing logins via the Disqus social provider (wpdiscuz or disqus as the login method) from unfamiliar IP addresses or at unusual times; sudden administrator-level actions (plugin installs, user creation) shortly after a Disqus-authenticated session.
  • Network: Requests to the wpDiscuz Disqus callback/authentication endpoint from unexpected geographic locations or IP ranges.
  • WordPress Admin: Unexpected changes to site settings, new administrator accounts created, or new plugins/themes installed following a Disqus login event.
  • File System: New or modified PHP files in the WordPress plugins or themes directories that were not part of a legitimate update, potentially indicating backdoor installation post-compromise (WPScan).

Mitigation and workarounds

Update the Comments – wpDiscuz plugin to version 7.6.40 or later, which contains the fix for this vulnerability. As an interim workaround, disable the Disqus social login provider in the plugin settings (/wp-admin/admin.php?page=wpdiscuz_options_page&wpd_tab=social) until the update can be applied. Site administrators should also audit recent logins via the Disqus provider for any suspicious activity and review administrator account integrity (WPScan).

Community reactions

The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for December 8–14, 2025, and included in Sucuri's January 2026 vulnerability patch roundup, indicating broad awareness within the WordPress security community. The WPScan advisory was verified by the WPScan team and includes a researcher-submitted proof-of-concept with a public demonstration video, lending credibility to the severity assessment (Wordfence Blog, Sucuri Blog).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management