CVE-2026-42749: WordPress Disable Comments for Any Post Types (Remove comments) plugin <= 1.3.0 - Broken Authentication vulnerability
Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types (Remove comments) comments-plus allows Password Recovery Exploitation.This issue affects Disable Comments for Any Post Types (Remove comments): from n/a through <= 1.3.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42749?
The severity of CVE-2026-42749 is rated as high with a CVSS score of 7.1.
What type of vulnerability is CVE-2026-42749?
CVE-2026-42749 is a Broken Authentication vulnerability in the Themeisle Disable Comments for Any Post Types plugin.
How does CVE-2026-42749 affect the Disable Comments for Any Post Types plugin?
CVE-2026-42749 allows for password recovery exploitation through an authentication bypass using an alternate path or channel.
Which versions of the Disable Comments for Any Post Types plugin are affected by CVE-2026-42749?
CVE-2026-42749 affects versions from n/a through 1.3.0 of the Disable Comments for Any Post Types plugin.
How can I fix CVE-2026-42749?
To fix CVE-2026-42749, update the Disable Comments for Any Post Types plugin to the latest version beyond 1.3.0.