Incorrect authorization in WordPress - #VU151457
Published: September 20, 2026
Vulnerability details
The vulnerability allows a remote user to reparent comments onto posts they cannot edit.
The vulnerability exists due to improper authorization in comment reparenting functionality when processing requests to reparent comments. A remote user can send a request to reparent a comment they created on their own post to a post they cannot edit.
An Author role suffices for exploitation.