Unauthorized Data Modification in WordPress Comments Import & Export Plugin
CVE-2025-3919
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 June 2025
What is CVE-2025-3919?
The Comments Import & Export plugin for WordPress is affected by a security issue that enables unauthorized users to modify data due to a missing capability check in the save_settings function. This vulnerability, present in versions up to 2.4.3, also stems from inadequate sanitization and escaping of FTP settings, allowing authenticated attackers with Subscriber-level access and above to inject malicious web scripts into the plugin's settings page. These scripts can then execute whenever an admin user accesses the modified page, posing severe risks to website integrity. The issue has been addressed in version 2.4.4.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WordPress Comments Import & Export * <= 2.4.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved