CVE-2026-105059: WordPress Delete All Comments of wordpress plugin <= 7.1 - Broken Access Control vulnerability
Subscriber Broken Access Control in Delete All Comments of wordpress <= 7.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Delete All Comments pluginto a version that resolves this vulnerability.Fixed in 7.2
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user with Subscriber-level access can exploit the broken access control. The attack can be performed over the network and does not require user interaction.
What is the likely impact of exploitation?
The reported impact is limited to availability, with no reported confidentiality or integrity impact. An attacker could affect comment availability through the plugin's comment-deletion functionality.
How can I determine whether my site is affected?
Check whether the WordPress Delete All Comments plugin is installed and whether its version is 7.1 or earlier. Those versions are identified as affected.