WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Comments Import & Export

WordPress Comments Import Export plugin is a fast way for export and import WordPress Comments.

6Reported vulnerabilities
9.8Highest CVSS score
2.5.2Latest version
2,000+Active installs

What to do now

Update Comments Import & Export to 2.5.0 or later. 6 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 17, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2018-11526 High 7.8 5.1% 2.0.4 and earlier 2.0.5 June 19, 2018
CVE-2022-45370 Critical 9.8 0.8% 2.3.1 and earlier 2.3.2 November 7, 2023
CVE-2024-7514 Medium 6.5 1.1% 0 to 2.3.7 (inclusive) 2.3.9 October 11, 2024
CVE-2025-3919 Medium 6.4 0.3% 0 to 2.4.3 (inclusive) 2.4.4 June 2, 2025
CVE-2026-32441 Medium 4.3 0.3% 2.4.9 and earlier 2.5.0 March 20, 2026
CVE-2024-31235 Medium 4.3 0.2% 2.3.5 and earlier 2.3.6 April 12, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.