CVE-2026-87839 UNKNOWN

CVE-2026-87839

Published: 2026-09-20

Description

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…