Unauthorized Data Modification in WordPress Comments Import & Export Plugin
CVE-2025-3919
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 June 2025
What is CVE-2025-3919?
The Comments Import & Export plugin for WordPress is affected by a security issue that enables unauthorized users to modify data due to a missing capability check in the save_settings function. This vulnerability, present in versions up to 2.4.3, also stems from inadequate sanitization and escaping of FTP settings, allowing authenticated attackers with Subscriber-level access and above to inject malicious web scripts into the plugin's settings page. These scripts can then execute whenever an admin user accesses the modified page, posing severe risks to website integrity. The issue has been addressed in version 2.4.4.
Affected Version(s)
WordPress Comments Import & Export * <= 2.4.3