CVE-2026-87839: Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion

Published Sep 20, 2026
·
Updated

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.

Affected Software

1 affected component
WordPress Tripzzy plugin<1.5.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WordPress Tripzzy plugin to a version that resolves this vulnerability.

    Fixed in 1.5.1
  2. Compensating control

    Temporarily restrict unauthenticated access to the affected AJAX action endpoint (block at the web server/WAF/edge) until the Tripzzy plugin is upgraded to 1.5.1, to prevent unauthenticated users from deleting comments.

Event History

Sep 20, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Which sites are exposed to exploitation?

Sites using the Tripzzy WordPress plugin in versions before 1.5.1 are exposed. The vulnerable AJAX action is available to unauthenticated users, so an attacker does not need a WordPress account.

2

What does an attacker need to delete comments?

An attacker only needs to send requests to the affected unauthenticated AJAX action and provide an identifier for a comment. Because the identifier is not validated and authorization checks are absent, arbitrary site comments can be permanently deleted.

3

Does this affect only comments created through Tripzzy?

No. The issue allows deletion of arbitrary comments on the site; the available information does not limit impact to comments associated with Tripzzy.

4

How can administrators determine whether they are affected?

Check whether the Tripzzy plugin is installed and whether its version is earlier than 1.5.1. Sites running an earlier version should treat their comments as at risk of unauthorized permanent deletion.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203