WP Security CheckVulnerability data as of October 7, 2026

Vulnerability alerts / October 6, 2026

Vulnerability in WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments — CVE-2026-105059

MediumSeverity
CVSS 6.5
0.4%Estimated exploit probability
EPSS
20,000+ sitesInstalls
7.2Fixed in

What to do now

Update WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments to 7.2 or later.

Affected versions

  • Everything up to and including 7.1

Affected: WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments (plugin, delete-all-comments-of-website)

Check: The plugin on wordpress.org / Our record for WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments

What the vulnerability is

Subscriber Broken Access Control in Delete All Comments of wordpress <= 7.1 versions.

This description is reproduced verbatim from the public vulnerability record.

Sources

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts