diff --git src/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php src/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php
index 15e18f7..aba6be0 100644
--- src/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php
+++ src/wp-includes/rest-api/endpoints/class-wp-rest-comments-controller.php
@@ -430,6 +430,11 @@ class WP_REST_Comments_Controller extends WP_REST_Controller {
 			return $prepared_comment;
 		}
 
+		// Do not allow comments to be created with non-whitelisted type.
+		if ( ! empty( $request['type'] ) && ! in_array( $request['type'], array( 'comment', 'pingback', 'trackback' ) ) ) {
+			return new WP_Error( 'rest_invalid_comment_type', __( 'Cannot create a comment with that type.' ), array( 'status' => 400 ) );
+		}
+
 		/*
 		 * Do not allow a comment to be created with missing or empty
 		 * comment_content. See wp_handle_comment_submission().
diff --git tests/phpunit/tests/rest-api/rest-comments-controller.php tests/phpunit/tests/rest-api/rest-comments-controller.php
index a0d87ff..34ebb3e 100644
--- tests/phpunit/tests/rest-api/rest-comments-controller.php
+++ tests/phpunit/tests/rest-api/rest-comments-controller.php
@@ -1034,6 +1034,32 @@ class WP_Test_REST_Comments_Controller extends WP_Test_REST_Controller_Testcase
 		$this->assertEquals( $comment_id, $collection_data[0]['id'] );
 	}
 
+	/**
+	 * @ticket 38820
+	 */
+	public function test_create_comment_with_invalid_type() {
+		$post_id = $this->factory->post->create();
+		wp_set_current_user( self::$admin_id );
+
+		$params = array(
+			'post'    => $post_id,
+			'author'       => self::$admin_id,
+			'author_name'  => 'Comic Book Guy',
+			'author_email' => 'cbg@androidsdungeon.com',
+			'author_url'   => 'http://androidsdungeon.com',
+			'content' => 'Worst Comment Ever!',
+			'date'    => '2014-11-07T10:14:25',
+			'type' => 'foo',
+		);
+
+		$request = new WP_REST_Request( 'POST', '/wp/v2/comments' );
+		$request->add_header( 'content-type', 'application/json' );
+		$request->set_body( wp_json_encode( $params ) );
+
+		$response = $this->server->dispatch( $request );
+		$this->assertErrorResponse( 'rest_invalid_comment_type', $response, 400 );
+	}
+
 	public function test_create_comment_invalid_email() {
 		$post_id = $this->factory->post->create();
 		wp_set_current_user( self::$admin_id );
