Executive brief
The Tripzzy WordPress plugin before version 1.5.1 contains a vulnerability that allows unauthenticated users to permanently delete any comments on a WordPress site. An attacker can exploit this through an unprotected AJAX function to remove comments without authorization, potentially damaging site reputation or removing important user feedback.
Technical details
The plugin fails to implement authorization checks and does not validate comment identifiers in an AJAX action accessible to unauthenticated users. This broken access control vulnerability (CWE-284) allows an attacker to craft requests that delete arbitrary comments without authentication. The issue is patched in version 1.5.1.
Affected products
- Tripzzy Tripzzy before 1.5.1
Timeline
- 2026-09-18: disclosed
- 2026-09-20: advisory
- 2026-09-20: patched: Fixed in version 1.5.1