= Comments - wpDiscuz v7.6.72 - 07.10.2026 = * Fixed: A comment whose image was refused for its width or height was saved anyway, and the error message was empty. The `wpdiscuz_mu_preupload` action now fires before the comment is saved, so a file it refuses stops the comment. * Fixed: The on/off switches on the settings page showed their state by color alone and could not be used from the keyboard. They now show a cross when off and a check mark when on, and can be reached with Tab and toggled with Space. Switches in addon settings tabs get the same fix. = Comments - wpDiscuz v7.6.71 - 16.09.2026 = * Fixed: The comment bubble and the live comment update never showed comments posted without an email address to visitors who have no email address themselves, visitors who have not commented yet and guests who comment anonymously. A visitor's own new comments are left out of these updates by their email address, and an empty address matched every comment posted without one, so anonymous commenters were hidden from each other and from everyone who has not commented. The email address is now only used when the visitor has one, a guest commenting anonymously keeps their own comments out of the update through the ones already on their screen. * Fixed: The new comment message of the comment bubble described the newest comment of the post, even when the bubble was not notifying about that comment, the visitor's own comment or one already on their screen. It now describes the newest comment the visitor is being notified about, and is left out of the response when that comment cannot be read, a private comment an addon keeps from the visitor for instance, where it used to be built from nothing. * Fixed: The Cookies Consent and Agreement checkbox labels were printed on the comment form, and on the comment edit form, without being escaped. The labels are cleaned when the form is saved, but that only applies to what is saved from then on, so a label stored before v7.6.13 kept whatever markup it was given and was still printed as markup to every visitor. The labels are now filtered where they are printed, the agreement label by the same rules its own save path allows and the cookies consent label by a narrow set that keeps links and inline formatting, so a label that still holds script no longer runs it. The field name is escaped in the wrapper class of the cookies consent and text area fields as well, as it already was in the other field types. * Fixed: The info icon of the "powered by wpDiscuz" line below the comments carried its behaviour in an inline onclick attribute, which a Content Security Policy that forbids inline script blocks outright, leaving the icon unresponsive with nothing to explain why. It also reached the link through fixed element ids, so a page showing more than one comment form always toggled the first one, and it could not be reached from the keyboard at all. The icon is now handled from wpdiscuz.js, is operable by keyboard, toggles the block it belongs to, and moves focus to the link it reveals. * Fixed: The minimal theme carried none of the styles for the "powered by wpDiscuz" line. That stylesheet loads instead of the default theme one rather than alongside it, so the wpDiscuz link was shown permanently and unstyled, and the info icon beside it toggled nothing a reader would notice. * Fixed: The HTML field printed its markup on the comment form without being filtered. The markup is cleaned when the form is saved, but that only applies to what is saved from then on, so an HTML field stored before v7.6.13 kept whatever markup it was given and was still printed as markup to every visitor, and cloning a form or importing one copies such a value across untouched. It is now filtered where it is printed, by the same rules its own save path allows, so a field that still holds script no longer runs it. Its code is shown as plain text until the field is cleared. The number field description is escaped where it is printed as well, as it already was in the other field types. * Fixed: The titles of the comment editor toolbar buttons were passed through the translation function a second time where they are printed, against wpDiscuz's own text domain. The titles are already translated by that point, so the title of a button added by an addon was looked up in a text domain it does not belong to, and a title the addon had already escaped was escaped a second time, which shows the escape sequence itself to the reader in any title holding an apostrophe or an ampersand. The titles are now only escaped where they are printed. * Fixed: The icon height and the tab title of each card on the settings dashboard, and the icon class of the file attachment button on the comment form, were printed without being escaped. All three are supplied through settings arrays and filters an addon can extend, so a value holding a quote or a tag was printed as markup rather than as the value it was meant to be. They are now escaped where they are printed, as the values beside them already were. * Fixed: Replies from guests were rejected as spam on sites where an anti-spam plugin fills in its own hidden fields with JavaScript once the page loads, La Sentinelle for instance, while the first comment posted through the main form went through. A reply form is built by copying the markup of a hidden form on the page, and markup carries the values the page was served with rather than the ones those scripts set, so every reply went out with an untouched honeypot and timer. A second comment from the main form was rejected the same way, because the form is cleared after a comment is posted and clearing it put those fields back to the values the page was served with. The values the scripts set are now carried into every reply form, and kept when the form is cleared. * Fixed: Every comment a guest posted was rejected while "Detect spambots posting comments" is enabled in All In One Security, stored as spam or discarded depending on its settings. That option rejects a guest comment that arrives without its hidden antibot keys, and it adds those keys only to the comment form WordPress prints itself. wpDiscuz now prints them in its comment, reply and inline feedback forms whenever the option is on. As with the WordPress comment form, a page served from a full-page cache can still carry keys that have expired since, and does not set the cookies its optional cookie check needs. * Fixed: Inline feedback comments were sent without the fields anti-spam plugins add to comment forms. The feedback form is loaded after the page, and those plugins only add their fields to the comment form, so a plugin that treats a missing field as spam, La Sentinelle for instance, rejected every feedback comment from a guest. A feedback comment is now sent with the Akismet and La Sentinelle fields of the comment form on the same page. The new `wpdiscuz_antispam_field_prefixes` filter adds the input and textarea fields of other plugins by the start of their names, and the same list decides which fields keep their values when a comment form is cleared. * Fixed: Sending a comment again after it was stored as spam showed WordPress's "Duplicate comment detected" error instead of wpDiscuz's message for a rejected comment. WordPress refuses a comment identical to one it has already stored, spam included, and that refusal was passed on to the commenter as it was. The retry now gets the rejected comment message, "Your comment was not published." by default, and nothing new is stored. The `wpdiscuz_comment_rejected_response` filter runs for the retry as well, with the earlier comment and a new fourth argument set to true, so a plugin that explained the first rejection can tell the retry apart. A comment that repeats a published one, or one awaiting approval, still shows the duplicate error. = Comments - wpDiscuz v7.6.70 - 11.09.2026 = * Fixed: Vote buttons showed guests the wrong state and tooltip when "Allow Guests to Vote for Comments" is disabled (buttons looked active, or blamed the visitor's IP address, then clicking answered "You Must Be Logged In To Vote"). * Fixed: Guests whose IP address is removed by a privacy plugin or a `pre_comment_user_ip` filter all shared a single post-rating identity. The first such guest locked the rating for every other one, or overwrote it when "Enable rate editing" is enabled, and they were all counted as one rating in the post average and rating count. Guest rating now requires a usable IP address, the same way comment voting has since 7.6.67. * Fixed: The "Enable rate editing" form setting never reached the front-end script, so the confirmation before changing an existing rating was never asked. The form settings were read one line before they were loaded. * Added: The `wpdiscuz_post_rating()` template tag prints the standalone Article Rating anywhere in a theme or page builder template, and `wpdiscuz_get_post_rating()` returns the same HTML. Pass a post ID to display that post's rating with its own form settings, or pass false as the second argument for read-only output. WooCommerce products continue to use WooCommerce's own rating. * Added: The `[wpdiscuz_post_rating]` shortcode provides the same output for page builders and content editors, with `post_id`, `can_rate`, and `page_rating` attributes. Disable unneeded built-in Article Rating positions to avoid displaying the rating more than once. * Fixed: Pages displaying more than one Article Rating repeated the `wpd-post-rating` id and sent every rating click to the post of the page. Each rating is now a `.wpd-post-rating` element carrying its own post ID, so any eligible post can be rated wherever the wpDiscuz script is loaded. The legacy id remains on the page's own rating at the first checked built-in position, or on a manual placement when no position is checked. * Fixed: The Article Rating schema was repeated whenever the page's own rating appeared more than once. It now follows the rating that owns the legacy id. The template tag's third argument and the shortcode's `page_rating` attribute can explicitly give or deny a manual placement that ownership when the settings cannot determine it. * Fixed: "Display ratings on non-singular pages" loaded a stylesheet that did not style the Article Rating block. The standalone rating styles now cover it and use the configured star colours, allowing template-tag and shortcode ratings to display read-only on archives, listings, and other pages where the wpDiscuz script is not loaded when that option is enabled. * Fixed: Selecting comment attachments more than once replaced the files already selected. New selections now accumulate up to the configured limit, and duplicate files are ignored. = Comments - wpDiscuz v7.6.69 - 07.09.2026 = * Fixed: Logging in with X (Twitter) ended on a blank page showing "0" instead of signing the visitor in. The callback URL and the requested scopes were placed in the authorization request without being URL-encoded. * Fixed: The Stick and Close actions under a comment on the WordPress Comments page never completed. The requests carried no wpDiscuz nonce, so they were rejected with "Nonce is invalid." and the button spinner kept turning. Both buttons also restore their icon now when a request fails, instead of spinning forever. * Improved: The Google social login button now uses the official multicolor Google "G" logo. = Comments - wpDiscuz v7.6.68 - 03.09.2026 = * Added: The `wpdiscuz_comment_rejected_response` filter lets moderation plugins provide a clear explanation when a new comment is stored as spam or trash. * Fixed: Main and inline comment forms now show a moderation plugin's rejection explanation while keeping the standard wpDiscuz spam or trash phrase when no plugin provides one. * Fixed: Inline comments stored as spam or trash no longer create subscription records or send mention notifications. * Fixed: Comment insertion failures, including duplicate-comment and flood checks, now return a valid AJAX error instead of terminating the request with an unusable response. * Fixed: Plus signs and encoded data are preserved in inline commenter names and email addresses, the comment-author email cookie, and submitted website URLs. * Improved: The Phrases screen now identifies the spam and trash rejection fields separately. * Improved: Voting buttons now stay visible in a disabled state for visitors who cannot vote on a comment, instead of being hidden. Hiding them left visitors unaware that the site has voting at all. The buttons carry a `wpd-vote-disabled` class and a tooltip with the reason, and clicking one still shows the existing message. * Added: The `wpdiscuz_hide_readonly_vote_buttons` filter hides those buttons again, restoring the `wpd-vote-readonly` markup used before this release. * Security: The Google Client Secret is no longer included in the front-end JavaScript settings. = Comments - wpDiscuz v7.6.67 - 29.08.2026 = * Fixed: Registered users can vote independently when they share an IP address, while registered authors are still blocked from voting on their own comments with the correct message. * Fixed: Guests no longer fall into one shared voting identity when privacy software removes visitor IP addresses. Affected guests must log in to vote even when guest voting is enabled. * Added: The `wpdiscuz_deny_vote_from_same_ip` filter lets site owners show voting buttons and allow votes for same-IP guest comments without changing registered-user voting. Guests on that IP still share one voting identity. * Fixed: Vote totals remain visible when voting buttons are hidden by self-vote restrictions, and `wpdiscuz_show_vote` can now reliably hide other eligible voting components. * Fixed: Disabling comment voting now blocks the vote action through both native WordPress AJAX and the custom wpDiscuz AJAX endpoint. * Improved: The voting settings now explain the global request gate and IP-based guest identity, including shared-IP behavior and the login requirement when no visitor IP is available. * Note: Existing vote records and totals are preserved; this update changes future voting behavior and does not recalculate historical votes. = Comments - wpDiscuz v7.6.66 - 27.08.2026 = * Security: Fixed an unauthenticated comment disclosure vulnerability in AJAX comment loading. Reported by Jakub Herman via WPScan. = Comments - wpDiscuz v7.6.65 - 25.08.2026 = * Added: The Reviews add-on teaser lists the new "Allow guest reviews" option. * Improved: The settings search shows which email a result belongs to. Eight options are labelled "Email subject" and eight "Email content", so a search for "email" returned an indistinguishable list; every result now carries its section, such as "Subscription Type: Post new comment". * Improved: The settings search also matches those section names, so searching for "mentioned" or "follow confirmation" finds the email templates belonging to them. * Improved: A settings search result for one of the email templates now opens the accordion holding it, instead of leaving the option hidden behind a collapsed panel. * Fixed: A settings search result for an option inside a collapsed accordion scrolled to the top of the page instead of to the option, because the scroll measured the option row while it was still hidden and a hidden row reports a position of zero. * Fixed: Clicking a second settings search result belonging to an accordion that was already open closed it, because the accordion was toggled rather than opened. * Fixed: The Reviews add-on teaser said the WooCommerce ratings import skips guest reviews. The import includes them. * Fixed: The Reviews add-on teaser described the review gate as limiting who may submit a review. It sets submitted reviews to pending and does not vet users. * Added: wpdScrollToOption() is exposed on the window object, so an add-on whose options sit in an accordion of its own can scroll to an option once it has opened it. * Fixed: The comment editing information printed only the edit icon, without the name of the editor and the time of the edit, on websites whose phrases table does not contain the "Last edited %1$s by %2$s" phrase. * Improved: Saved phrases are now merged into the default phrases instead of replacing them. Phrases introduced by a plugin update are no longer printed empty on websites where the phrases table has not been filled with them yet, which happens when the plugin is updated without the WordPress dashboard ever being opened. * Improved: The comment editing information is not printed at all when its phrase is empty, instead of printing a lone edit icon which tells nothing about who edited the comment and when. * Removed: The Phrases settings page had fields for the VKontakte and Odnoklassniki share button titles. Those share buttons are no longer part of wpDiscuz and the two phrases behind the fields were neither defined nor saved anywhere, so the page raised an "Undefined array key" warning on every load. * Fixed: Visitors whose email address contains an apostrophe could not subscribe to comments. The address was checked for validity before the backslash WordPress puts in front of the apostrophe was removed, so the subscription form rejected it and reported nothing. * Fixed: Comment subscriptions were looked up by matching the email address as a SQL pattern instead of comparing it exactly. Since the % and _ characters are allowed in an email address, a subscriber using such an address matched the other subscribers of the same post, received their unsubscribe link, and removed their comment thread subscriptions. = Comments - wpDiscuz v7.6.64 - 07.08.2026 = * Improved: Allowed file types and thumbnail sizes are now validated against the known allowed lists when the Content settings are saved, so only values offered by the settings form itself can be stored. * Improved: Imported options files are now validated before being stored. File types are checked against the mime types WordPress allows to be uploaded, so an edited options file cannot introduce an executable file type. File types provided by add-ons are preserved even when the add-on is not active at the moment of the import. * Fixed: Searching the settings page for a term containing an apostrophe returned no results. * Improved: The request sanitizing helpers now return the supplied default value when a request parameter is an array or an object instead of the expected string. * Removed: An unused method on the add-ons page which read a request parameter without checking that it was set. = Comments - wpDiscuz v7.6.63 - 07.08.2026 = Fixed: An issue with comment editing( current_user_can('moderate_comments') ) when comments are closed = Comments - wpDiscuz v7.6.62 - 30.07.2026 = * Improved: Additional HTML tag escaping when comment editor phrases are printed into inline JavaScript. * Fixed: Imported phrase files were not sanitized on upload, unlike phrases saved from the Phrases settings page. * Fixed: The comments block editor preview could be triggered on the front-end without an editing capability check. = Comments - wpDiscuz v7.6.60/v7.6.61 - 27.07.2026 = * Fixed: Stored XSS vulnerability in the comment image URL conversion. Image URLs are now escaped for HTML attribute output. Thanks to hieus for responsibly reporting the issue. * Fixed: Missing escaping on the custom URL field value and the default avatar image URL. * Fixed: A leftover debug function call in the default avatar handler. = Comments - wpDiscuz v7.6.59 - 03.07.2026 = * Fixed: An issue preventing the proper deletion of attachments. * Fixed: An Undefined index warning triggered during the active theme file validation check. = Comments - wpDiscuz v7.6.58 - 10.06.2026 = * Fixed: Missing escaping issues * Fixed: Internal images were missing in the combined version of the CSS = Comments - wpDiscuz v7.6.57 - 07.06.2026 = * Fixed: Low-severity security issues * Fixed: Attachment delete AJAX dereferences a missing comment before validation * Fixed: Bubble live-update AJAX renders arbitrary comment IDs without per-comment authorization * Fixed: Post-rating AJAX accepts ratings outside the five-star range * Fixed: Show-replies AJAX dereferences an invalid comment ID without validation = Comments - wpDiscuz v7.6.56 - 27.05.2026 = * Fixed: Some addons are deactivated after an update on some sites/hosting providers = Comments - wpDiscuz v7.6.55 - 26.05.2026 = * Fixed: An issue with wpDiscuz nonce validation * Fixed: An issue with WooCommerce integration (The form was not rendered even if the user has bought a product) * Fixed: An issue with wpDiscuz Ratings regeneration in the tools page * Fixed: The issues with wpDiscuz tools * Fixed: An issue with email notifications checking - wc_msg_ip_mismatch * Fixed: An issue when a comment was approved after editing * Added: A new jQuery event 'wpdiscuz_before_send_comment' before ajax request is sent * Added: A new jQuery event 'wpdiscuz_comment_post_success' ajax request is sent, and comment is added * Added: A new jQuery event 'wpdiscuz_comment_post_error' ajax request is sent, but comment adding failed * Added: A new jQuery event 'wpdiscuz_comment_post_failed' ajax request is sent, but unknown error occurred (System Fail, Network Fail, etc) * Added: A new jQuery event 'wpdiscuz comment _post complete' ajax request is sent and complete (This does not state if the comment was added or not, it just fires when the request is complete) = Comments - wpDiscuz v7.6.51-v7.6.54 - 10.04.2026 = * Fixed: An issue with wpDiscuz nonce validation = Comments - wpDiscuz v7.6.50 - 02.04.2026 = * Fixed: An issue with wpDiscuz nonce validation * Added: Load wpDiscuz comments for block themes automatically * Added: Support for attachment preview replace (no need to re-upload all attachments anymore) = Comments - wpDiscuz v7.6.49 - 26.03.2026 = * Fixed: The images in the comments were displayed twice. = Comments - wpDiscuz v7.6.48 - 21.03.2026 = * Added: A new filter hook "wpdiscuz_show_vote" to allow hiding/showing vote buttons for certain comments. * Added: A new filter hook "wpdiscuz_post_attachments_as_gallery" to allow controlling whether a post's attachments should be displayed as a gallery or not. * Fixed: Prevent adding unnecessary statistics on comment deletion. * Fixed: Guests can't vote on guest comments. * Fixed: Issue with adding nonce in cookies that leads to an issue with nonce verification. = Comments - wpDiscuz v7.6.47 - 11.03.2026 = * Security: Unauth Email Notification Flood via wpdCheckNotificationType * Security: Stored XSS in Inline Comment Preview * Security: Shortcode Injection via Email Notifications * Security: Stored XSS via Malicious Options Import * Security: SQL Injection in getAllSubscriptions() * Security: Vote Manipulation via Nonce Oracle and IP Rotation * Security: IP Spoofing in getIP() * Security: Destructive GET Action — Delete All Comments by Email * Security: Options Export Leaks OAuth Secrets in Plaintext * Security: Unsanitized Cookie Email Used as wp_mail() Recipient * Security: XSS via Unescaped Custom CSS in