Authentication Bypass in Themeisle Disable Comments Plugin
CVE-2026-42749
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 May 2026
What is CVE-2026-42749?
An authentication bypass vulnerability exists in the Themeisle Disable Comments for Any Post Types (Remove comments) plugin, potentially allowing unauthorized users to access and exploit password recovery functionality. This flaw affects versions from n/a up to and including 1.3.0, enabling attackers to bypass authentication mechanisms through specific alternate paths, posing a significant risk to site security.
Affected Version(s)
Disable Comments for Any Post Types (Remove comments) 0 <= 1.3.0