CVE-2018-11526: Webtoffee WordPress Comments Import And Export

High severity, CVSS 7.8. EPSS: 5.1% chance of exploitation in the next 30 days.

The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.

Affected products

  • Webtoffee WordPress Comments Import And Export: up to and including 2.0.4

Published 2018-06-19. Last modified 2026-06-17.