Description
The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.
Published: 2026-09-20
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Permanent deletion of user comments
Action: Immediate Patch
AI Analysis

Impact

Tripzzy, a WordPress plugin, contains an AJAX endpoint that can be invoked by anyone without authentication. The code that processes the deletion ignores authorization checks and does not validate the comment identifier supplied by the requester. An attacker can therefore craft requests that target any comment ID, resulting in the permanent removal of that comment. The vulnerability does not provide a path to execute code or exfiltrate data; its impact is limited to loss of user‑generated content.

Affected Systems

WordPress installations running Tripzzy version 1.4.x or earlier are affected. Any site that has not upgraded to version 1.5.1 or later will continue to expose the unchecked AJAX action and therefore remains vulnerable.

Risk and Exploitability

Exploitation requires only the ability to send an HTTP request to the site, making the attack straightforward for unauthenticated users. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, but the CVSS score of 7.5 reflects a high severity due to the permanent data loss. The vulnerability is not cataloged in CISA’s KEV list, so there is no current evidence of widespread active exploitation.

Generated by OpenCVE AI on September 20, 2026 at 16:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Tripzzy plugin to version 1.5.1 or later to restore proper authorization checks and ID validation.
  • If an immediate upgrade is not possible, disable the plugin or block its AJAX endpoint for unauthenticated users, for example by adding a rule in the site’s firewall or by editing the .htaccess file to restrict access to /wp-admin/admin-ajax.php requests that include the Tripzzy action.
  • As a temporary containment measure, remove the plugin entirely until a secure update can be applied.

Generated by OpenCVE AI on September 20, 2026 at 16:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions tripzzy
Vendors & Products Wordpress-extensions
Wordpress-extensions tripzzy

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.
Title Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion
References

Subscriptions

Wordpress-extensions Tripzzy
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-20T13:50:17.890Z

Reserved: 2026-09-09T11:22:36.182Z

Link: CVE-2026-87839

cve-icon Vulnrichment

Updated: 2026-09-20T13:50:01.000Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T07:16:50.760

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-87839

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:48:37Z

Weaknesses