← Back to CVE List
CVE-2026-87836Wordfence
Vulnerability Summary
The Comments Import & Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions 2.1.11 to 2.5.3. This makes it possible for authenticated attackers, with author-level access and above, to extract sensitive user or configuration data.
CVSS v3.1 Base Metrics — Score 4.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityNone
AvailabilityNone
Affected & Patched Versions
- Comments Import & Export 2.1.11 - 2.5.3
- Comments Import & Export 1