Loading market data...
← Back to CVE feed

CVE-2026-87839

HIGH CVSS 7.5 View on NVD ↗

Description

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Published: Sep 20, 2026 07:16 UTC Modified: Sep 20, 2026 14:16 UTC