plugin

Comments Import Export Woocommerce Vulnerabilities

14 known security issues reported for the Comments Import Export Woocommerce WordPress plugin. Most recent disclosed Mar 25, 2026.

1 high 6 medium

Running Comments Import Export Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Comments Import &amp; Export [comments-import-export-woocommerce] <= 2.4.9 (unfixed)

unknown

[en] Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comments Import & Export: from n/a through <= 2.4.9.

Affected:
up to 2.4.9
Fix:
No patched version reported
Disclosed:
Mar 25, 2026

CVE-2026-32441 on NVD →

Comments Import & Export <= 2.4.9 - Missing Authorization

medium

The Comments Import & Export plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.4.9
Fixed in:
2.5.0
Disclosed:
Mar 20, 2026

CVE-2026-32441 on NVD →

WordPress Comments Import & Export <= 2.4.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The WordPress Comments Import & Export plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings function in all versions up to, and including, 2.4.3. Additionally, the plugin fails to properly sanitize and escape FTP settings parameters. This makes...

CVSS:
6.4
Affected:
up to 2.4.3
Fixed in:
2.4.4
Disclosed:
Jun 2, 2025

CVE-2025-3919 on NVD →

Comments Import &amp; Export [comments-import-export-woocommerce] < 2.3.9

unknown

[en] The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to read t...

Affected:
up to 2.3.9
Fixed in:
2.3.9
Disclosed:
Oct 11, 2024

CVE-2024-7514 on NVD →

WordPress Comments Import & Export <= 2.3.7 - Authenticated (Author+) Arbitrary File Read via Directory Traversal

medium

The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to read the co...

CVSS:
6.5
Affected:
up to 2.3.7
Fixed in:
2.3.9
Disclosed:
Oct 10, 2024

CVE-2024-7514 on NVD →

Comments Import &amp; Export [comments-import-export-woocommerce] < 2.3.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.5.

Affected:
up to 2.3.6
Fixed in:
2.3.6
Disclosed:
Apr 12, 2024

CVE-2024-31235 on NVD →

WordPress Comments Import & Export <= 2.3.5 - Cross-Site Request Forgery

medium

The WordPress Comments Import & Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.5. This is due to missing or incorrect nonce validation on the do_export() function. This makes it possible for unauthenticated attackers to trigger an export via a forged re...

CVSS:
4.3
Affected:
up to 2.3.5
Fixed in:
2.3.6
Disclosed:
Apr 5, 2024

CVE-2024-31235 on NVD →

Comments Import &amp; Export [comments-import-export-woocommerce] < 2.3.2

unknown

[en] Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.1.

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Nov 7, 2023

CVE-2022-45370 on NVD →

WordPress Comments Import & Export <= 2.3.1 - CSV Injection

medium

The WordPress Comments Import & Export plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.3.1. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with...

CVSS:
6.1
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
Feb 6, 2023

CVE-2022-45370 on NVD →

WebToffee Plugins <= (Various Versions) - Arbitrary User Creation

high

The users-customers-import-export-for-wp-woocommerce plugin (and other Webtoffee plugins) before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.

CVSS:
8.8
Affected:
up to 2.1.11
Fixed in:
2.1.11
Disclosed:
Mar 11, 2020

CVE-2020-12074 on NVD →

Comments Import &amp; Export [comments-import-export-woocommerce] < 2.1.11

unknown

Cross-Site Request Forgery (CSRF) vulnerability discovered by WordFence in WordPress Comments Import & Export plugin (versions <= 2.1.10).

Affected:
up to 2.1.11
Fixed in:
2.1.11
Disclosed:
Mar 11, 2020

WordPress Comments Import & Export <= 2.0.4 - CSV Injection

medium

The WordPress Comments Import & Export plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.0.4 via the form fields. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on...

CVSS:
6.1
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Jun 21, 2018

CVE-2018-11526 on NVD →

Comments Import &amp; Export [comments-import-export-woocommerce] < 2.0.5

unknown

[en] The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Jun 19, 2018

CVE-2018-11526 on NVD →

Comments Import &amp; Export [comments-import-export-woocommerce] < 2.4.4

unknown
Affected:
up to 2.4.4
Fixed in:
2.4.4

CVE-2025-3919 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database