The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Tripzzy WordPress plugin before version 1.5.1 contains a critical authorization bypass vulnerability that allows unauthenticated attackers to permanently delete arbitrary comments from affected websites. The vulnerability stems from missing authorization checks and insufficient input validation in an AJAX action endpoint, enabling any user—including those without any account credentials—to submit requests that delete comments by manipulating object identifiers. This affects all WordPress sites running the vulnerable plugin version, potentially impacting content integrity, user engagement, and site reputation as attackers can selectively remove legitimate user comments, feedback, or reviews without authentication.
While this CVE has no direct MITRE ATT&CK technique mapping, Casky's Claude-powered security skills would identify the underlying attack patterns through detection of CWE-284 (Improper Access Control) violations. Practitioners using Casky would observe findings related to unauthenticated action execution, improper privilege enforcement, and object-level authorization failures. The platform's extended reasoning capability would help security teams recognize the attack chain: reconnaissance of AJAX endpoints, exploitation of missing auth checks, and privilege escalation through anonymous access. A Casky analysis would flag the absence of nonce verification, capability checks (is_user_logged_in), and object ownership validation—key defensive controls—allowing practitioners to remediate similar authorization flaws across their WordPress infrastructure before exploitation occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-87839. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation