PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87836 WordPress.org CVE debrief

The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP addresses, unapproved comment content and comment meta.

Vendor
WordPress.org
Product
Comments Import & Export
CVSS
LOW 2.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

WordPress site administrators, security teams, and users with Author role or above should assess exposure and potential impact. Site owners should verify plugin version and user role configurations. Security teams should review comment data accessibility and potential misuse. Users with Author role or above should be aware of the potential for unauthorized data exposure.

Why it matters

CVE-2026-87836 allows users with Author role and above to export all comments on a WordPress site, potentially exposing sensitive data. Defenders should verify exposure, assess impact, and consider upgrading to plugin version 2.5.4 or later.

  • Potential unauthorized data exposure through comment export
  • Possible misuse of commenter email addresses and IP addresses
  • Risk of sensitive comment content disclosure
  • Need for verification of plugin version and user role configurations

Technical summary

The Comments Import & Export WordPress plugin before 2.5.4 does not restrict comment export to users able to moderate comments or scope the export to content owned by the requesting user. This allows users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP addresses, unapproved comment content, and comment meta. The vulnerability affects WordPress sites with the plugin installed and users with Author role or above, potentially exposing sensitive comment data.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact, especially for WordPress sites with Author role users or above.

Recommended defensive actions

  • Verify WordPress site exposure by checking plugin version and user roles
  • Assess potential impact by reviewing comment data accessible to Author role users
  • Consider upgrading to plugin version 2.5.4 or later
  • Monitor for potential misuse of exported comment data
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but limited information is available on exploitation or affected versions. Defenders should verify plugin version, user roles, and comment data accessibility. Limited source information exists on potential impact or mitigation effectiveness. Further review of WordPress site configurations and user role settings is necessary.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87836 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87836

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87836 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87836

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.