Unrated severityNVD Advisory· Published Sep 17, 2026
CVE-2026-87836
CVE-2026-87836
Description
The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP addresses, unapproved comment content and comment meta.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.5.4
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.