Comments Import & Export [comments-import-export-woocommerce] <= 2.4.9 (unfixed)
unknown
[en] Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comments Import & Export: from n/a through <= 2.4.9.
- Affected:
- up to 2.4.9
- Fix:
- No patched version reported
- Disclosed:
- Mar 25, 2026
CVE-2026-32441 on NVD →
Comments Import & Export <= 2.4.9 - Missing Authorization
medium
The Comments Import & Export plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.4.9
- Fixed in:
- 2.5.0
- Disclosed:
- Mar 20, 2026
CVE-2026-32441 on NVD →
WordPress Comments Import & Export <= 2.4.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The WordPress Comments Import & Export plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings function in all versions up to, and including, 2.4.3. Additionally, the plugin fails to properly sanitize and escape FTP settings parameters.
This makes...
- CVSS:
- 6.4
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.4
- Disclosed:
- Jun 2, 2025
CVE-2025-3919 on NVD →
Comments Import & Export [comments-import-export-woocommerce] < 2.3.9
unknown
[en] The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to read t...
- Affected:
- up to 2.3.9
- Fixed in:
- 2.3.9
- Disclosed:
- Oct 11, 2024
CVE-2024-7514 on NVD →
WordPress Comments Import & Export <= 2.3.7 - Authenticated (Author+) Arbitrary File Read via Directory Traversal
medium
The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to read the co...
- CVSS:
- 6.5
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.9
- Disclosed:
- Oct 10, 2024
CVE-2024-7514 on NVD →
Comments Import & Export [comments-import-export-woocommerce] < 2.3.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.5.
- Affected:
- up to 2.3.6
- Fixed in:
- 2.3.6
- Disclosed:
- Apr 12, 2024
CVE-2024-31235 on NVD →
WordPress Comments Import & Export <= 2.3.5 - Cross-Site Request Forgery
medium
The WordPress Comments Import & Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.5. This is due to missing or incorrect nonce validation on the do_export() function. This makes it possible for unauthenticated attackers to trigger an export via a forged re...
- CVSS:
- 4.3
- Affected:
- up to 2.3.5
- Fixed in:
- 2.3.6
- Disclosed:
- Apr 5, 2024
CVE-2024-31235 on NVD →
Comments Import & Export [comments-import-export-woocommerce] < 2.3.2
unknown
[en] Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.1.
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Nov 7, 2023
CVE-2022-45370 on NVD →
WordPress Comments Import & Export <= 2.3.1 - CSV Injection
medium
The WordPress Comments Import & Export plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.3.1. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with...
- CVSS:
- 6.1
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Feb 6, 2023
CVE-2022-45370 on NVD →
WebToffee Plugins <= (Various Versions) - Arbitrary User Creation
high
The users-customers-import-export-for-wp-woocommerce plugin (and other Webtoffee plugins) before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
- CVSS:
- 8.8
- Affected:
- up to 2.1.11
- Fixed in:
- 2.1.11
- Disclosed:
- Mar 11, 2020
CVE-2020-12074 on NVD →
Comments Import & Export [comments-import-export-woocommerce] < 2.1.11
unknown
Cross-Site Request Forgery (CSRF) vulnerability discovered by WordFence in WordPress Comments Import & Export plugin (versions <= 2.1.10).
- Affected:
- up to 2.1.11
- Fixed in:
- 2.1.11
- Disclosed:
- Mar 11, 2020
WordPress Comments Import & Export <= 2.0.4 - CSV Injection
medium
The WordPress Comments Import & Export plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.0.4 via the form fields. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on...
- CVSS:
- 6.1
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Jun 21, 2018
CVE-2018-11526 on NVD →
Comments Import & Export [comments-import-export-woocommerce] < 2.0.5
unknown
[en] The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Jun 19, 2018
CVE-2018-11526 on NVD →
Comments Import & Export [comments-import-export-woocommerce] < 2.4.4
unknown
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.4
CVE-2025-3919 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database