A vulnerability described as critical has been identified in multicollab Plugin up to 5.2 on WordPress. This vulnerability affects the function cf_add_comment . Such manipulation leads to missing authorization. This vulnerability is traded as CVE-2025-4202 . The attack may be launched remotely. There is no exploit available. Upgrading the affected component is recommended.