---
id: CVE-2026-87839
title: >-
  The Tripzzy  WordPress plugin before 1.5.1 does not have authorisation checks,
  and does not validate the identifier of the object being removed, in an AJAX
  action available to unauthenticated users, allowing them to permanently delete
  ar…
summary: >-
  The Tripzzy  WordPress plugin before 1.5.1 does not have authorisation checks,
  and does not validate the identifier of the object being removed, in an AJAX
  action available to unauthenticated users, allowing them to permanently delete
  ar…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-284
product: Tripzzy
affected:
  - Tripzzy >= 1.1.8 < 1.5.1
published: '2026-09-20'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:34:57.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87839'
references:
  - url: 'https://wpscan.com/vulnerability/e5145602-cb5e-4ef9-a51b-8f161200d014/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00208
epssPercentile: 0.11279
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-20T13:50:15.337205Z'
ingestedAt: '2026-09-20T07:16:12.221Z'
---

## Overview

The Tripzzy  WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
