
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32441 is a Missing Authorization vulnerability in the WebToffee Comments Import & Export WordPress plugin (slug: comments-import-export-woocommerce). It allows network-based attackers with low-level privileges to exploit incorrectly configured access control security levels, bypassing intended restrictions on comment data operations. All plugin versions up to and including 2.4.9 are affected. The vulnerability was published on March 25, 2026, and carries a CVSS v3.1 base score of 7.7 (High) (Feedly, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization) — the plugin fails to properly verify whether a requesting user has the necessary permissions before executing sensitive import/export operations on comment data. The attack vector is network-based, requires low privileges (an authenticated user with minimal access), no user interaction, and has a changed scope, meaning the impact extends beyond the vulnerable component itself. The flaw falls under the OWASP category of Broken Access Control, where security-sensitive functionality is exposed without adequate capability or role checks (Feedly, Patchstack).
Successful exploitation results in a high confidentiality impact with no integrity or availability impact, meaning an attacker can read or export sensitive comment data — including potentially private or moderated comments — without authorization. Because the scope is marked as changed, the impact can extend beyond the plugin itself to affect the broader WordPress site or associated WooCommerce data. This could expose customer communications, order-related comments, or other sensitive user-generated content stored in the WordPress comments system (Feedly).
The vulnerability requires only low-level authentication (e.g., a subscriber or customer account), making it accessible to a wide range of potential attackers on sites with open user registration. The EPSS score is approximately 0.017%, indicating a currently low probability of active exploitation in the wild. No public proof-of-concept exploit code, exploit kit integration, or confirmed in-the-wild exploitation has been reported as of the available data. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
comments-import-export-woocommerce plugin at version ≤ 2.4.9 using tools like WPScan or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/comments-import-export-woocommerce/readme.txt./wp-admin/admin-ajax.php) or plugin-specific REST API routes associated with comments-import-export-woocommerce from low-privilege user sessions..csv or .xml comment dumps) generated in the WordPress uploads directory or plugin directory.Users should update the Comments Import & Export plugin to a version above 2.4.9 as soon as a patched release is available from WebToffee. As an interim workaround, site administrators can disable the plugin until a patch is applied, or restrict user registration to prevent untrusted low-privilege accounts from being created. Additionally, implementing a Web Application Firewall (WAF) rule to block unauthorized access to plugin-specific endpoints can reduce exposure (Patchstack, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."