Known vulnerabilities in AnyComment
AnyComment is blazing-fast commenting plugin based on React for WordPress.
7Reported vulnerabilities
8.8Highest CVSS score
0.3.6Latest version
5,000+Active installs
What to do now
Update AnyComment to 0.2.18 or later.
4 of these have a fixed version available. Updating resolves them.
This plugin has not been updated in over two years. New vulnerabilities may never be fixed. Consider an alternative.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2022-0134 | High | 0.6% | Before 0.2.18 | 0.2.18 |
February 21, 2022 |
| CVE-2021-24838 | Medium | 2.2% | Before 0.3.5 | 0.3.5 |
January 17, 2022 |
| CVE-2025-60240 | High | 0.4% | 0.3.6 and earlier | — | July 12, 2025 |
| CVE-2022-0279 | Low | 0.5% | Before 0.2.18 | 0.2.18 |
February 21, 2022 |
| CVE-2025-48091 | Medium | 0.4% | 0.3.6 and earlier | — | October 8, 2025 |
| CVE-2018-21001 | Medium | 0.9% | Before 0.0.33 | 0.0.33 |
August 27, 2019 |
| CVE-2025-62874 | Medium | 0.3% | 0.3.6 and earlier | — | December 31, 2025 |