← back
CVE-2020-13640observed exploitation

CVE-2020-13640

45Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 13%
from disclosure to weapon
Published on NVDJun 18
VulnCheck+171d
exploitation probability
13%top 4% of all CVEs
observed exploitation
yesVulnCheck
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)
Affected products
n/a · n/a