No Page Comment

No Page Comment has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2022; all 2 are fixed as of September 2026. Their average CVSS score is 7.5, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2022 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.

Every one of the 2 issues recorded for No Page Comment has a vendor fix available, so running the current release closes all known holes.

No Page Comment is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSHigh
7.5/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all No Page Comment vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8

No Page Comment <= 1.1 - Cross-Site-Request Forgery to Settings Change

Read the full analysis

Vulnerability Records

2 records
No Page Comment banner
Latestv1.3.1

No Page Comment

Seth Alling

Author

Seth Alling

5.0(22)
100/100
Last Updated
2025-11-17 (10mo ago)
Active Installs
10,000+
Downloads
254,732
Requires WP
6.2+
Requires PHP
7.4+
Tested up to
WP 6.8.8
Created
2011-09-06 (15y ago)

Up until recently, WordPress gave two options: You could either disable comments and trackbacks by default for all pages and posts, or you could have them active by default. In WordPress version 4.3, this finally changed so comments are always disabled on new pages. While the new change makes it easier for many of the sites, it make it harder for people who need to get the reverse and enable comments on all pages, or if they need to change the default for a custom post type. This plugin allows you to choose whether comments are enabled or disabled by default on all new posts, pages and custom post types, while still giving the ability to individually enable comments on posts or pages. Also, this plugin provides a way to quickly disable all comments or pingbacks for a specific custom post type. It directly interacts with your database to modify the status, so it is highly recommended that you backup your database first. There shouldn’t be any issues using this feature, but it’s always good to play it safe. View No Page Comment Development on Github Please Report any Issues about No Page Comment on Github Donate to Support No Page Comment Development

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C