Authentication Bypass in Tripzzy Plugin for WordPress
CVE-2026-87839
Currently unrated
Key Information:
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2026-87839?
The Tripzzy WordPress plugin lacks proper authorization checks, allowing unauthenticated users to access an AJAX action. This security flaw enables malicious actors to permanently delete arbitrary comments from a website, posing a significant risk to content integrity and site management.
Affected Version(s)
Tripzzy 1.1.8 < 1.5.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.