Impact
The Comments Import & Export WordPress plugin does not restrict its export functionality to users who can moderate comments, nor does it restrict the export to content owned by the user making the request. As a result, users with the Author role and higher are able to download every comment on the site, including commenter email addresses, IP addresses, unapproved comment content, and comment meta. The attacker could thereby obtain personally identifying information and sensitive discussion data that should be protected.
Affected Systems
WordPress sites using the Comments Import & Export plugin version 2.1.11 up to 2.5.3 are affected. These versions are vulnerable to the data export exploitation described here. Sites that have not upgraded to version 2.5.4 or later remain at risk.
Risk and Exploitability
The CVSS score of 2.7 indicates low severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is the plugin’s export endpoint, which can be accessed by authenticated users with the Author role or above. If the attacker gains such access, they can retrieve full comment data without restriction.
OpenCVE Enrichment