WordPress Plugin Vulnerabilities

Magic Export & Import < 1.2.0 - Unauthenticated PII Disclosure

Description

The plugin stores exported CSV files at a publicly accessible location, making it possible for any visitors to leak sensitive user information.

Proof of Concept

Affects Plugins

Fixed in 1.2.0

References

YouTube Video

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
Hoang Phuong
Submitter
Hoang Phuong
Verified
Yes

Timeline

Publicly Published
2026-04-13 (about 21 days ago)
Added
2026-04-13 (about 20 days ago)
Last Updated
2026-04-13 (about 20 days ago)

Other