Description
WordPress Plugin Disqus Comment System is prone to multiple cross-site request forgery vulnerabilities. Exploiting these issues may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Disqus Comment System version 2.77 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.78 or latest
References
https://vexatioustendencies.com/csrf-in-disqus-wordpress-plugin-v2-77/
https://wordpress.org/plugins/disqus-comment-system/changelog/
Related Vulnerabilities
WordPress Plugin Simple Popup Newsletter Cross-Site Scripting (1.4.7)
WordPress Plugin AccessPress Social Icons Multiple Cross-Site Scripting Vulnerabilities (1.5.5)
Oracle Application Server CVE-2010-0070 Vulnerability (CVE-2010-0070)
concrete5 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-5107)