Themeisle Comments Plus Plugin Authentication Bypass Vulnerability

Vulnerability

An authentication bypass vulnerability has been identified in the Themeisle Disable Comments for Any Post Types (Remove Comments) Comments Plus plugin, specifically in versions through 1.3.0. This vulnerability allows for the exploitation of password recovery mechanisms, potentially leading to unauthorized access or actions.

Impact

Exploitation of this vulnerability could result in unauthorized access to user accounts or the ability to manipulate comments without proper authentication.

Added: May 27, 2026, 11:32 AM
Updated: May 27, 2026, 11:32 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
9.3
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.