Extension WordPress
Vulnérabilités Comments Import & Export
Cette page rassemble les failles publiées pour Comments Import & Export, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Comments Import & Export
7 fiches
Comments Import & Export <= 2.4.9 – Missing Authorization
The Comments Import & Export plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.9. This makes it possible for authenticated attackers, with…
*-2.4.9
2.5.0
20/03/2026
WordPress Comments Import & Export <= 2.4.3 – Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
The WordPress Comments Import & Export plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings function in all versions up to, and including, 2.4.3. Additionally, the plugin fails…
*-2.4.3
2.4.4
02/06/2025
WordPress Comments Import & Export <= 2.3.7 – Authenticated (Author+) Arbitrary File Read via Directory Traversal
The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7. This makes it possible…
*-2.3.7
2.3.9
10/10/2024
WordPress Comments Import & Export <= 2.3.5 – Cross-Site Request Forgery
The WordPress Comments Import & Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.5. This is due to missing or incorrect nonce validation on the do_export() function. This makes…
*-2.3.5
2.3.6
05/04/2024
WordPress Comments Import & Export <= 2.3.1 – CSV Injection
The WordPress Comments Import & Export plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.3.1. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code…
*-2.3.1
2.3.2
06/02/2023
WebToffee Plugins <= (Various Versions) – Arbitrary User Creation
The users-customers-import-export-for-wp-woocommerce plugin (and other Webtoffee plugins) before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
[*, 2.1.11)
2.1.11
11/03/2020
WordPress Comments Import & Export <= 2.0.4 – CSV Injection
The WordPress Comments Import & Export plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.0.4 via the form fields. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which…
*-2.0.4
2.0.5
21/06/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.