Impact
The Comments Import & Export plugin fails to check the user’s capability on the save_settings function and does not properly sanitize FTP settings parameters. Consequently, any authenticated user with Subscriber-level access or higher can insert arbitrary scripts into the plugin’s settings page. When an administrator later opens that page, the injected scripts run in the administrator’s browser, enabling the attacker to modify data, deface the site, or potentially elevate privileges through additional client‑side attacks.
Affected Systems
All installations of the webtoffee Comments Import & Export WordPress plugin up to and including version 2.4.3 are vulnerable. Versions 2.4.4 and newer contain the required capability check and parameter sanitization and are not affected.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of widespread exploitation in the near term. The exploit requires authenticated access with at least Subscriber rights, so the attack surface is limited to sites that allow such roles. The vulnerability is not listed in the CISA KEV catalog, meaning there is no known large‑scale exploitation currently reported.
OpenCVE Enrichment
EUVD