Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]

Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] has one disclosed vulnerability in the WordSec catalog, all reported in 2014; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] has a vendor fix available, so running the current release closes it.

All of these findings were reported by Mallory Adams. Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] is installed on roughly 1,000,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSHigh
8.8/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2014-2550

Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] < 1.0.4 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] banner
Latestv2.9.0

Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]

WPDeveloper

Author

WPDeveloper

4.7(280)
94/100
Last Updated
2026-09-01 (12d ago)
Active Installs
1,000,000+
Downloads
35,179,358
Requires WP
5.0+
Requires PHP
7.0+
Tested up to
WP 7.0.4
Created
2011-05-27 (16y ago)

Disable Comments – Remove Comments & Stop Spam [Multi-Site Support] Enable/Disable comments on any WordPress content (Pages, Posts, or Media) to stop spammers. WP-CLI, XML-RPC & REST-API support to stop spam comments. More About Plugin ◼️ Documentation ◼️ Support Forum Take Global Control Over Your WordPress Site Override all comments-related settings throughout your website & manage your comments just the way you want. Disable Comments On Posts, Pages & Media Choose which posts, pages or media should allow comments from site visitors & configure Disable Comments accordingly Disallow Comments On Multi-Site Network Have multiple websites? Get rid of irrelevant comments on the entire network using Disable Comments Plugin KEY FEATURES OF DISABLE COMMENTS All “Comments” links are hidden from the Admin Menu and Admin Bar. All comment-related sections (“Recent Comments”, “Discussion” etc.) are hidden from the WordPress Dashboard. All comment-related widgets are disabled (so your theme cannot use them). The “Discussion” settings page is hidden. All comment RSS/Atom feeds are disabled (and requests for these will be redirected to the parent post). The X-Pingback HTTP header is removed from all pages. Outgoing pingbacks are disabled. Stop spam comments entirely from the site with one click. Delete comments by type, including WooCommerce product reviews. Disable comments via XML-RPC & REST-API Fully Multi-site Network supported. Manage multiple website network-specific subsites or entire network comments in advance. Exclude Disable Comments Settings based on user roles. Keep the WordPress 6.9+ Block Editor “Notes” comment type working while every other comment stays off. [New in 2.8.0] AI-agent ready: supports the WordPress Abilities API (WP 6.9+), so AI assistants and MCP clients can read your comment settings. Please delete any existing comments on your site before applying this setting, otherwise (depending on your theme) those comments may still be displayed to visitors. You can use the Delete Comments tool to delete any existing comments on your site. 🌟 WHAT’S NEW WITH DISABLE COMMENTS 2.0 AMAZING USER FRIENDLY INTERFACE Easily configure your comment-related settings with an amazing and attractive app-like user interface. WP-CLI COMMANDS TO DISABLE COMMENTS Use WP-CLI control for comment-related settings to disable comments on posts, pages, attachments or everywhere on your website. GET STARTED WITH QUICK SETUP WIZARD Use the quick setup wizard after activating the plugin to instantly configure comment-related settings for your WordPress website. DISABLE COMMENTS ON DOCS Instantly disable comments on your documentation pages or WordPress knowledge base with a single click. DELETE CERTAIN COMMENT TYPE(S) Permanently delete certain comment types from your WordPress website including WooCommerce product reviews as well as generic comments. DISABLE COMMENTS VIA XML-RPC And REST API Block any comments made on your WordPress website via XML-RPC specification and REST API. Important note: Use this plugin if you don’t want comments at all on your site (or on certain post types). Don’t use it if you want to selectively disable comments on individual posts – WordPress lets you do that anyway. If you don’t know how to disable comments on individual posts, there are instructions in the FAQ. If you come across any bugs or have suggestions, please use the plugin support forum. I can’t fix it if I don’t know it’s broken! Please check the FAQ for common issues. Want to contribute? Here’s the GitHub development repository. A must-use version of the plugin is also available. Advanced Configuration Some of the plugin’s behavior can be modified by site administrators and plugin/theme developers through code: Define DISABLE_COMMENTS_REMOVE_COMMENTS_TEMPLATE and set it to false to prevent the plugin from replacing the theme’s comment template with an empty one. Define DISABLE_COMMENTS_ALLOW_DISCUSSION_SETTINGS and set it to true to prevent the plugin from hiding the Discussion settings page. These definitions can be made either in your main wp-config.php or in your theme’s functions.php file. THIS PLUGIN IS NOW MAINTAINED BY THE TEAM WPDeveloper. 💙 LOVED DISABLE COMMENTS? For documentation and tutorials go to our Documentation For video tutorials go to our YouTube Playlist Join our Facebook Group If you love Disable Comments, rate us on WordPress For more information about features, FAQs, and documentation, check out our website at Disable Comments 🔥 GET FREEBIES FOR YOUR WORDPRESS SITE Consider checking out our other WordPress solutions & boost your WordPress website: 🔝 Essential Addons For Elementor: Most popular Elementor addons with 2 million+ happy users & 95+ widgets & ready blocks 🔔 NotificationX – Best Social Proof & FOMO Marketing Solution to increase conversion rates. 🔗 BetterLinks: Latest best WordPress link management plugin for link shortening, tracking & analyzing. 📄 EmbedPress: EmbedPress lets you embed anything including videos, images, posts, audio, maps and upload PDF, DOC, PPT etc. ☁ Templately: 6000+ Free templates library for Elementor & Gutenberg along with the cloud collaboration for WordPress. 📚 BetterDocs: Best Documentation & Knowledge Base Plugin for WordPress reduce manual support tickets & improve user experience. ⏰ SchedulePress: Advanced editorial calendar with WordPress Post Scheduling, Social Sharing, Missed scheduled alerts, and more. ⚡ Flexia: Most lightweight, customizable & multi purpose theme for WordPress. Visit WPDeveloper to learn more about how to do better in WordPress with Help Tutorial, Tips & Tricks. Source Code The JavaScript and CSS shipped in assets/ are compiled with Grunt and Babel from uncompiled sources that are not included in the plugin zip: JavaScript in src/ and Sass in assets/scss/. Both the sources and the build configuration live in the GitHub development repository. To build them yourself: npm install npm run build

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C