Description
The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP addresses, unapproved comment content and comment meta.
Published: 2026-09-17
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The Comments Import & Export WordPress plugin does not restrict its export functionality to users who can moderate comments, nor does it restrict the export to content owned by the user making the request. As a result, users with the Author role and higher are able to download every comment on the site, including commenter email addresses, IP addresses, unapproved comment content, and comment meta. The attacker could thereby obtain personally identifying information and sensitive discussion data that should be protected.

Affected Systems

WordPress sites using the Comments Import & Export plugin version 2.1.11 up to 2.5.3 are affected. These versions are vulnerable to the data export exploitation described here. Sites that have not upgraded to version 2.5.4 or later remain at risk.

Risk and Exploitability

The CVSS score of 2.7 indicates low severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is the plugin’s export endpoint, which can be accessed by authenticated users with the Author role or above. If the attacker gains such access, they can retrieve full comment data without restriction.

Generated by OpenCVE AI on September 18, 2026 at 01:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Comments Import & Export plugin to version 2.5.4 or later.
  • Configure the plugin (or a security plugin) to allow comment export only for Administrator roles, or disable the export feature entirely for non‑administrators.
  • Apply application‑layer filtering or a web‑application firewall rule to block export requests from non‑admin users.
  • Monitor comment export traffic for abnormal activity and review logs for potential misuse of the export function.

Generated by OpenCVE AI on September 18, 2026 at 01:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP addresses, unapproved comment content and comment meta.
Title Comments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via Export
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:28:29.854Z

Reserved: 2026-09-09T11:18:55.524Z

Link: CVE-2026-87836

cve-icon Vulnrichment

Updated: 2026-09-17T12:11:39.985Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T06:16:51.880

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-87836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:00:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor