CVE-2014-5345
Disqus Comment System < 2.75 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.
Exploits (1)
References (5)
Scores
EPSS
0.0239
EPSS Percentile
84.8%
Classification
CWE
CWE-79
Status
draft
Affected Products (32)
disqus/disqus_comment_system
< 2.75
disqus/disqus_comment_system
disqus/disqus_comment_system
disqus/disqus_comment_system
disqus/disqus_comment_system
disqus/disqus_comment_system
disqus/disqus_comment_system
disqus/disqus_comment_system
disqus/disqus_comment_system
disqus/disqus_comment_system
disqus/disqus_comment_system
disqus/disqus_comment_system
disqus/disqus_comment_system
disqus/disqus_comment_system
disqus/disqus_comment_system
... and 17 more
Timeline
Published
Aug 19, 2014
Tracked Since
Feb 18, 2026