Junglewise Threat Intelligence

CVE-2026-42749: Themeisle Disable Comments for Any Post Types auth bypass

CVE-2026-42749 · Severity: high · CVSS 7.1 · Published 2026-05-27

Vendors: Themeisle.

Executive brief

A security vulnerability exists in a WordPress plugin used to manage and disable comments across a website. This flaw allows an attacker to bypass standard security checks during the password recovery process. If exploited, this could lead to unauthorized account access or service disruption, potentially compromising the site's administrative control.

Technical details

The Themeisle Disable Comments for Any Post Types (Remove comments) plugin for WordPress is vulnerable to an Authentication Bypass Using an Alternate Path or Channel (CWE-288). The flaw exists within the 'comments-plus' component and specifically impacts the password recovery workflow. An attacker with low-level privileges can exploit this alternate path to bypass authentication requirements. This can lead to unauthorized password resets or exploitation of the recovery mechanism. The issue affects all versions up to and including 1.3.0.

Affected products

  • Themeisle Disable Comments for Any Post Types (Remove comments) <= 1.3.0

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References