---
id: CVE-2026-87836
title: >-
  The Comments Import & Export WordPress plugin before 2.5.4 does not restrict
  its comment export to users able to moderate comments, nor scope the export to
  content owned by the requesting user, allowing users with the Author role and
  abo…
summary: >-
  The Comments Import & Export WordPress plugin before 2.5.4 does not restrict
  its comment export to users able to moderate comments, nor scope the export to
  content owned by the requesting user, allowing users with the Author role and
  abo…
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
product: Comments Import & Export
affected:
  - comments_import_export >= 2.1.11 < 2.5.4
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87836'
references:
  - url: 'https://wpscan.com/vulnerability/ed416bc1-27b7-4840-953a-e0aa925b9336/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00316
epssPercentile: 0.21865
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T12:12:40.303494Z'
ingestedAt: '2026-09-17T06:12:17.974Z'
---

## Overview

The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP addresses, unapproved comment content and comment meta.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
