Comments – wpDiscuz
by AdvancedCoding · Forms
Advanced AJAX-powered WordPress comments plugin with live commenting, comment voting, inline feedback, social login, custom comment forms, and engagem …
82 health vs 63 average across 1,679 Forms plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Biggest win: Support resolution
To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
114.5K
now · peak 165.5K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
26
releases in the last 12 months
2mo ago
latest release · v7.6.59
221
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 89% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “60K+”. Our estimate pins where the real number sits.
Modeled within the band wp.org reports; tightens as we track daily.
Install history · since 2015-03-11 · 1,500 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. The recent download trend is too spiky to read.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ bellakaroo7mo ago
Day 2 I managed after a day and half to get rid of the “fill in the required fields” message that popup for users wherether logged in or not, its the rich editor and the name and email field that causes this issue. If I make the name field required and the email optional and deactivate the rich editor on both desktip and mobile then the message dissappear but now it creates 2 new issue. Star ratings are not clickable and comment nesting for replies doesn’t work eventhough the feature is turned on in wp discussion tab. If you reply to a comment the comment gets posted as an individual /standalone comment at the top of the comment section and not as a nested reply. Honestly, I’m done struggling. I fix 1 thing and multiple other stuff breaks in your plugin! I’m now dropping star ratings because of the additional issues that now arised. —— Day 1 The plugin is nice, especially the star ratings but it’s a nightmare to setup. The whole day I’ve tried to get the plugin not to show “input too short” and “fill in the required fields” error messages. My input is set to min 1 and unlimited to max so basically the default settings but it gives the error of “input too short” so I changed it from 1 to 2 min and from unlimited to 1000 max and finally the message stopped. But now it gives the “fill in the required fields” error. I unticked the option in the wp discussion tab for users must fill in their name and email before they can comment. Great. Now I disabled the required field in the wpdiscuz default form field for name and email. It worked once. I closed out of my site, opened it again and navigated to a post and tried to comment and theres the “fill in the required fields” block, so I fill in the name eventhough it’s not required anymore and the email and hit the button and there’s the message again. There’s nothing left to fill in. I changed the comment requirements to users must be logged in, now the name and email boxes vanish but I still can’t comment, the same error message popup. I even went as far to disable everything in the wordpress discussion tab, cleared the cache and cookies, logged in via incognito and my tablet on another email and still get the same error message. I deactivated all my plugins and still same message. I don’t use jetpack so it can’t be their comment form thing causing conflicts. I switched from my kadence theme to the default twenty-five theme and same error. It works once. There’s no restrictions setup to how many times someone can comment either. Guests that comment needs to fill out the name and email box everytime they want to reply to a thread, aint filling it in once enough until they leave the page? Only thing I want is for logged out users not to be able to comment under the anonymous lable. I’m about to uninstall the plugin as I can’t be bothered to struggle this much with it. It’s definitely not worth spending another day trying to get rid of those messages. I’m not a developer, and before I spend money on hiring one just to make a plugin work, I’d rather just not use it. This topic was modified 6 months ago by bellakaroo.
Read on wp.org ↗ - ★★★★★ mbellinger8mo ago
Downloaded the Plugin today.Installation, Setup easy, is up & running in a few minutes, perhaps not perfect within these few minutes, but working.Goog overview, goog presentation of settings.Best of all – it is free of charge obviously 🙂 – Thank you Developers !Collecting experience now…
Read on wp.org ↗ - ★★★★★ Olaf Lederer9mo ago
After an upgrade to php 8.3 the plugin broke my customer’s website. It took some discussions here at WP.org to convince the plugin’s team to add more validations into their code.But after they fixed it the PHP errors are gone. Thanks!
Read on wp.org ↗ - ★★★★★ Grant10mo ago
wpDiscuz is user-friendly, pretty light as a plugin, and has a ton of add-ons. The support staff are very efficient too. Give wpDiscuz a try.
Read on wp.org ↗ - ★★★★★ Willem Jurka11mo ago
I have been using wpDiscuz for a long time and I’m very satisfied with it. The plugin is reliable, user-friendly and offers everything I need for managing comments on my site.
Read on wp.org ↗ - ★★★★★ tierschutzmato12mo ago
Ein wirklich guter support. Und auch das Script finde ich super.
Read on wp.org ↗ - ★★★★★ c12gene1.0y ago
They just pack too much junk into this app. I can’t even figure out how to delete comments…there is so much nonsense even the basic stuff is confusing
Read on wp.org ↗ - ★★★★★ ZoBabe1.0y ago
Seem like you can do pretty much anything! And if you get stuck, the support forum is extremely responsive and helpful.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 6.59 Fixed: An issue preventing the proper deletion of attachments. Fixed: An Undefined index warning triggered during the active theme file validation check. 6.59
- — Version 6.58 Fixed: Missing escaping issues Fixed: Internal images were missing in the combined version of the CSS 6.58
- — Version 6.57 Fixed: Low-severity security issues Fixed: Attachment delete AJAX dereferences a missing comment before validation Fixed: Bubble live-update AJAX renders arbitrary comment IDs without per-comment authorization Fixed: Pos 6.57
- — Version 6.60 Fixed: Stored XSS vulnerability in the comment image URL conversion. Image URLs are now escaped for HTML attribute output. Thanks to hieus for responsibly reporting the issue. Fixed: Missing escaping on the custom URL fi 6.60
- — Version 6.62 Improved: Additional HTML tag escaping when comment editor phrases are printed into inline JavaScript. Fixed: Imported phrase files were not sanitized on upload, unlike phrases saved from the Phrases settings page. Fixed 6.62
- — Version 6.63 Fixed: An issue with comment editing( current_user_can(‘moderate_comments’) ) when comments are closed 6.63
Known vulnerabilities
via Wordfence Intelligence26 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-07-02 CVE-2026-9148 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.6.56 Patched in 7.6.57
- 2026-03-12 CVE-2026-22209 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.6.46 Patched in 7.6.47
- 2025-12-25 CVE-2025-68997 Authorization Bypass Through User-Controlled Key Affects <= 7.6.42 Patched in 7.6.44
- High · 8.1 Comments – wpDiscuz <= 7.6.39 - Unauthenticated Authentication Bypass Through Account Takeover ↗2025-12-11 CVE-2025-13820 Authorization Bypass Through User-Controlled Key Affects <= 7.6.39 Patched in 7.6.40
- Medium · 4.3 wpDiscuz <= 7.6.33 - Missing Authorization ↗
- Critical · 9.8 Comments – wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider ↗2024-10-24 CVE-2024-9488 Authentication Bypass Using an Alternate Path or Channel Affects <= 7.6.24 Patched in 7.6.25
- 2024-08-01 CVE-2024-6704 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.6.21 Patched in 7.6.22
- Medium · 6.4 Comments – wpDiscuz <= 7.6.18 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2024-06-06 CVE-2024-35681 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.6.18 Patched in 7.6.19
- Medium · 6.4 wpDiscuz <= 7.6.15 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Alternative Text ↗2024-04-22 CVE-2024-2477 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.6.15 Patched in 7.6.16
- 2023-11-17 CVE-2023-51691 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.6.12 Patched in 7.6.13
- Medium · 4.3 wpDiscuz <= 7.6.11 - Cross-Site Request Forgery ↗
- 2023-10-31 CVE-2023-47185 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.6.11 Patched in 7.6.12
- 2023-10-22 CVE-2023-46311 Authorization Bypass Through User-Controlled Key Affects <= 7.6.3 Patched in 7.6.4
- 2023-10-22 CVE-2023-46310 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 7.6.10 Patched in 7.6.11
- 2023-09-18 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 7.6.6 Patched in 7.6.6
- Medium · 5.3 wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Post Rating Increase/Decrease ↗2023-09-12 CVE-2023-3998 Authorization Bypass Through User-Controlled Key Affects <= 7.6.3 Patched in 7.6.4
- Medium · 5.3 wpDiscuz <= 7.6.3 - Insecure Direct Object Reference to Comment Rating Increase/Decrease ↗2023-09-12 CVE-2023-3869 Authorization Bypass Through User-Controlled Key Affects <= 7.6.3 Patched in 7.6.4
- 2022-10-28 CVE-2022-43492 Authorization Bypass Through User-Controlled Key Affects <= 7.4.2 Patched in 7.5
- 2022-02-10 CVE-2022-23984 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 7.3.11 Patched in 7.3.12
- 2021-09-13 CVE-2021-24737 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 7.3.0 Patched in 7.3.2
- Critical · 9.8 Comments - wpDiscuz 7.0 - 7.0.4 - Unauthenticated Arbitrary File Upload leading to Remote Code Execution ↗2021-06-06 CVE-2020-24186 Unrestricted Upload of File with Dangerous Type Affects 7.0 - 7.0.4 Patched in 7.0.5
- 2020-06-12 CVE-2020-13640 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 5.3.6 Patched in 5.3.6
- 2016-05-30 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.1.4 Patched in 3.2.0
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0
Languages
via translate.wordpress.orgTranslated into 52 languages, 2 at 90% or more
Plus 28 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-08-23 70K+ → 60K+ down after 120 days in tier
- 2026-04-25 80K+ → 70K+ down after 973 days in tier
- 2023-08-26 90K+ → 80K+ down after 18 days in tier
- 2023-08-08 80K+ → 90K+ up after 3 days in tier
- 2023-08-05 90K+ → 80K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Social comments by WpDevArt 8K+ installs · 4.2★ · 2 shared tags B -
AnyComment 5K+ installs · 4.7★ · 2 shared tags D
-
Advanced Comment Form 4K+ installs · 4.6★ · 2 shared tags C -
Comment Edit Core – Simple Comment Editing 2K+ installs · 4.7★ · 2 shared tags A -
FluentComments – Spam protection, AntiSpam, Ajax Enhanced Comments 700+ installs · 4.0★ · 2 shared tags C
-
Custom Comment Form Title 300+ installs · 4.1★ · 2 shared tags D
Embed this report card
Drop a live Pulse card for Comments – wpDiscuz into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/wpdiscuz" width="480" height="300" style="border:0" loading="lazy" title="Comments – wpDiscuz — Plugin Pulse"></iframe> Comments – wpDiscuz: 60K+ active installs, 4.7★ (578 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/wpdiscuz