PatchSiren cyber security CVE debrief
CVE-2026-87836 WordPress.org CVE debrief
The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP addresses, unapproved comment content and comment meta.
- Vendor
- WordPress.org
- Product
- Comments Import & Export
- CVSS
- LOW 2.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-17
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-17
- Advisory updated
- 2026-09-18
Who should care
WordPress site administrators, security teams, and users with Author role or above should assess exposure and potential impact. Site owners should verify plugin version and user role configurations. Security teams should review comment data accessibility and potential misuse. Users with Author role or above should be aware of the potential for unauthorized data exposure.
Why it matters
CVE-2026-87836 allows users with Author role and above to export all comments on a WordPress site, potentially exposing sensitive data. Defenders should verify exposure, assess impact, and consider upgrading to plugin version 2.5.4 or later.
- Potential unauthorized data exposure through comment export
- Possible misuse of commenter email addresses and IP addresses
- Risk of sensitive comment content disclosure
- Need for verification of plugin version and user role configurations
Technical summary
The Comments Import & Export WordPress plugin before 2.5.4 does not restrict comment export to users able to moderate comments or scope the export to content owned by the requesting user. This allows users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP addresses, unapproved comment content, and comment meta. The vulnerability affects WordPress sites with the plugin installed and users with Author role or above, potentially exposing sensitive comment data.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact, especially for WordPress sites with Author role users or above.
Recommended defensive actions
- Verify WordPress site exposure by checking plugin version and user roles
- Assess potential impact by reviewing comment data accessible to Author role users
- Consider upgrading to plugin version 2.5.4 or later
- Monitor for potential misuse of exported comment data
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but limited information is available on exploitation or affected versions. Defenders should verify plugin version, user roles, and comment data accessibility. Limited source information exists on potential impact or mitigation effectiveness. Further review of WordPress site configurations and user role settings is necessary.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87836 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87836
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87836 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87836
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/ed416bc1-27b7-4840-953a-e0aa925b9336/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.