Devs, can we please have an update on this question?
Bump on this. Can we please have an update?
Thread Starter
WPJEDI
(@cyrus100)
Just to follow up on this issue. Here is an update (not a direct one):
In version 2.77, these requests can be used to activate or deactivate the plugin, import and export comments, and sync comments between Disqus and a WordPress install. And without a proper nonce check, these requests can be made through the browser. I reached out to the Disqus team, and they assured me that the issue is being addressed and will hopefully patch the bug soon. If you have the Disqus plugin installed, keep your eyes out for an update in the near future.
http://torquemag.io/small-security-vulnerability-disqus-wordpress-plugin/
Any official response?
Any update? This is now months old. I’ve forwarded to the plugin security team for their review.
Dmatt here from Disqus Product Support. Thanks for reporting these issues to us. We’re currently aware and investigating further.
Update: the latest version of the Disqus plugin 2.79 includes a fix for the CSRF security issue here https://wordpress.org/plugins/disqus-comment-system/