← WordPress Vulnerabilities
WordPress security by component

Disable Comments for Any Post Types (Remove comments)

Disable Comments for Any Post Types (Remove comments) is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published May 27, 2026; the highest CVE/CNA score is 7.1.

Plugin slug: comments-plus

CVE-2026-42749: Disable Comments for Any Post Types (Remove comments): Privilege escalation or authentication bypass

Disable Comments for Any Post Types (Remove comments) is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 1.3.0.

PublishedMay 27, 2026
Known safe version1.3.1
Safe version
May 27, 2026 CVE-2026-42749
Disable Comments for Any Post Types (Remove comments): Privilege escalation or authentication bypass
Disable Comments for Any Post Types (Remove comments) is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 1.3.0.
1.3.1
CVE7.1
NVDPending