CVE-2026-87836: Comments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via Export
The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP addresses, unapproved comment content and comment meta.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Comments Import & Exportto a version that resolves this vulnerability.Fixed in 2.5.4
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with the Author role or a higher role can request the plugin's comment export. The user does not need permission to moderate comments or ownership of the content associated with those comments.
What information can be exposed through the export?
The export can disclose every comment on the site, including commenter email addresses, IP addresses, unapproved comment content, and comment metadata.
Are sites affected if Authors are not intended to manage comments?
Yes. The affected plugin versions do not enforce comment-moderation permission checks or limit exports to comments associated with content owned by the requesting user.
What version resolves the issue?
Upgrade the Comments Import & Export plugin to version 2.5.4 or later. Versions before 2.5.4 are affected.