🔐 CVE Alert

CVE-2026-87839

UNKNOWN 0.0

Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.

Vendor unknown
Product tripzzy
Published Sep 20, 2026
Stay Ahead of the Next One

Get instant alerts for unknown tripzzy

Be the first to know when new unknown vulnerabilities affecting unknown tripzzy are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Tripzzy
1.1.8 < 1.5.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/e5145602-cb5e-4ef9-a51b-8f161200d014/

Credits

Pablo González Pérez Francisco José Ramírez Vicente and Iñigo Sánchez Enciso WPScan