Executive brief
The AJAX Report Comments plugin for WordPress, which allows users to flag inappropriate comments, contains a security flaw that could allow an attacker to change the plugin's settings. By tricking a site administrator into clicking a malicious link, an attacker can modify notification email addresses, alert messages, and comment thresholds. This could lead to the redirection of administrative alerts to an attacker-controlled email or the disruption of the site's comment moderation system.
Technical details
The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the rc_options_page function. An unauthenticated attacker can exploit this by inducing a site administrator to perform an action, such as clicking a crafted link, which triggers a forged request to the server. Successful exploitation allows the attacker to modify various plugin configurations, including the notification email address, email subject/body, comment thresholds, and UI text. This vulnerability affects all versions up to and including 2.0.4.
Affected products
- WordPress AJAX Report Comments up to, and including, 2.0.4
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory