PT-2026-36778 · WordPress · Magic-Export-Import
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Magic Export & Import WordPress plugin versions prior to 1.2.0
Description
The plugin stores exported CSV files in a publicly accessible location. This allows unauthenticated visitors to leak sensitive user information or configuration data.
Recommendations
Update the plugin to version 1.2.0 or later.
Exploit
Fix
DoS
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Magic-Export-Import