Impact
Tripzzy, a WordPress plugin, contains an AJAX endpoint that can be invoked by anyone without authentication. The code that processes the deletion ignores authorization checks and does not validate the comment identifier supplied by the requester. An attacker can therefore craft requests that target any comment ID, resulting in the permanent removal of that comment. The vulnerability does not provide a path to execute code or exfiltrate data; its impact is limited to loss of user‑generated content.
Affected Systems
WordPress installations running Tripzzy version 1.4.x or earlier are affected. Any site that has not upgraded to version 1.5.1 or later will continue to expose the unchecked AJAX action and therefore remains vulnerable.
Risk and Exploitability
Exploitation requires only the ability to send an HTTP request to the site, making the attack straightforward for unauthenticated users. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, but the CVSS score of 7.5 reflects a high severity due to the permanent data loss. The vulnerability is not cataloged in CISA’s KEV list, so there is no current evidence of widespread active exploitation.
OpenCVE Enrichment