Themeisle Disable Comments for Any Post Types
- <= 1.3.0
An authentication bypass vulnerability has been identified in the Themeisle Disable Comments for Any Post Types (Remove Comments) Comments Plus plugin, specifically in versions through 1.3.0. This vulnerability allows for the exploitation of password recovery mechanisms, potentially leading to unauthorized access or actions.
Exploitation of this vulnerability could result in unauthorized access to user accounts or the ability to manipulate comments without proper authentication.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.