Unauthorized Data Modification in WordPress Comments Import & Export Plugin
CVE-2025-3919

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 June 2025

What is CVE-2025-3919?

The Comments Import & Export plugin for WordPress is affected by a security issue that enables unauthorized users to modify data due to a missing capability check in the save_settings function. This vulnerability, present in versions up to 2.4.3, also stems from inadequate sanitization and escaping of FTP settings, allowing authenticated attackers with Subscriber-level access and above to inject malicious web scripts into the plugin's settings page. These scripts can then execute whenever an admin user accesses the modified page, posing severe risks to website integrity. The issue has been addressed in version 2.4.4.

Affected Version(s)

WordPress Comments Import & Export * <= 2.4.3

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jörg Steinsträter
.