CVE-2026-32441
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-32441 is a Missing Authorization vulnerability in the WebToffee Comments Import & Export WordPress plugin (slug: comments-import-export-woocommerce). It allows network-based attackers with low-level privileges to exploit incorrectly configured access control security levels, bypassing intended restrictions on comment data operations. All plugin versions up to and including 2.4.9 are affected. The vulnerability was published on March 25, 2026, and carries a CVSS v3.1 base score of 7.7 (High) (Feedly, Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to properly verify whether a requesting user has the necessary permissions before executing sensitive import/export operations on comment data. The attack vector is network-based, requires low privileges (an authenticated user with minimal access), no user interaction, and has a changed scope, meaning the impact extends beyond the vulnerable component itself. The flaw falls under the OWASP category of Broken Access Control, where security-sensitive functionality is exposed without adequate capability or role checks (Feedly, Patchstack).

Impact

Successful exploitation results in a high confidentiality impact with no integrity or availability impact, meaning an attacker can read or export sensitive comment data — including potentially private or moderated comments — without authorization. Because the scope is marked as changed, the impact can extend beyond the plugin itself to affect the broader WordPress site or associated WooCommerce data. This could expose customer communications, order-related comments, or other sensitive user-generated content stored in the WordPress comments system (Feedly).

Exploitability

The vulnerability requires only low-level authentication (e.g., a subscriber or customer account), making it accessible to a wide range of potential attackers on sites with open user registration. The EPSS score is approximately 0.017%, indicating a currently low probability of active exploitation in the wild. No public proof-of-concept exploit code, exploit kit integration, or confirmed in-the-wild exploitation has been reported as of the available data. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the comments-import-export-woocommerce plugin at version ≤ 2.4.9 using tools like WPScan or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/comments-import-export-woocommerce/readme.txt.
  2. Obtain low-privilege access: Register or log in as a low-privileged user (e.g., subscriber or WooCommerce customer) on the target WordPress site.
  3. Identify vulnerable endpoints: Locate the plugin's import/export functionality endpoints or admin-ajax actions that lack proper capability checks.
  4. Send unauthorized request: Craft and send an authenticated HTTP request (with a valid nonce or session cookie) directly to the plugin's export endpoint, bypassing the intended access control restrictions.
  5. Exfiltrate comment data: Retrieve the exported comment data, which may include private, pending, or spam comments containing sensitive customer or order information (Feedly, Patchstack).

Indicators of compromise

  • Network: Unexpected HTTP GET or POST requests to WordPress admin-ajax endpoints (/wp-admin/admin-ajax.php) or plugin-specific REST API routes associated with comments-import-export-woocommerce from low-privilege user sessions.
  • Logs: WordPress access logs showing repeated requests to comment export/import endpoints from subscriber or customer-level accounts; unusual download of CSV/XML comment export files by non-administrator users.
  • File System: Unexpected export files (e.g., .csv or .xml comment dumps) generated in the WordPress uploads directory or plugin directory.
  • Process/Application: WordPress audit logs (if enabled via plugins like WP Activity Log) recording comment export actions performed by non-admin users.

Mitigation and workarounds

Users should update the Comments Import & Export plugin to a version above 2.4.9 as soon as a patched release is available from WebToffee. As an interim workaround, site administrators can disable the plugin until a patch is applied, or restrict user registration to prevent untrusted low-privilege accounts from being created. Additionally, implementing a Web Application Firewall (WAF) rule to block unauthorized access to plugin-specific endpoints can reduce exposure (Patchstack, Feedly).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management