CVE-2026-42749 HIGH

CVE-2026-42749: WordPress Disable Comments for Any Post Types (Remove comments) plugin <= 1.3.0 - Broken Authentication vulnerability

Vendor Themeisle
Product Disable Comments for Any Post Types (Remove comments)
Weakness CWE-288
Published May 27, 2026
Last update May 27, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

What the vulnerability does

01Description

Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types (Remove comments) comments-plus allows Password Recovery Exploitation.This issue affects Disable Comments for Any Post Types (Remove comments): from n/a through <= 1.3.0.

Explanation of Vulnerability in Simple Terms

02Summary

Disable Comments for Any Post Types version 1.3.0 and earlier contains an authentication bypass or privilege escalation flaw. An authenticated user with low privileges can modify site content or disable the site's availability. The vulnerability requires network access and valid login credentials but no additional user interaction.

What an attacker can do

03Attacker Capabilities

Modify site content or cause the site to become unavailable.

Potential impact on your site

04Site Impact

A low-privilege user can alter posts/pages or disrupt site availability without authorization.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account (e.g., subscriber or contributor role).

Key dates

06Disclosure timeline

May 27, 2026 CVE published
May 27, 2026 Record updated