Security patch has been released: 20160830

Note that by default Plone 4.1.x, 4.2.x, and 4.3.x use a version of plone.app.discussion that has this problem. Some remarks:

  • If you don't have comments enabled, you don't need to update.
  • Previous versions of the hotfix may seem to work, because the comment is not shown on the page anymore. But when you reload the page, the comment is still there.
  • If you have enabled comment moderation, then for new comments you can still bulk delete them on the moderation page.