WordPress · Magic-Export-Import · CVE-2026-5335
**Name of the Vulnerable Software and Affected Versions**
Magic Export & Import WordPress plugin versions prior to 1.2.0
**Description**
The plugin stores exported CSV files in a publicly accessible location. This allows unauthenticated visitors to leak sensitive user information or configuration data.
**Recommendations**
Update the plugin to version 1.2.0 or later.