CVE-2020-36505: Delete All Comments Easily Project Delete All Comments Easily

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which could result in an unauthenticated attacker making a logged in admin delete all comments from the blog.

Affected products

Published 2021-11-01. Last modified 2026-06-17.