CVE-2026-5335
Received
Received - Intake
Magic Export & Import WordPress Plugin Sensitive Data Exposure
Publication date: 2026-05-04
Last updated on: 2026-05-04
Assigner: WPScan
Description
Description
The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, making it possible for any visitors to leak sensitive user information.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| magic_export_import | magic_export_import | to 1.2.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-552 | The product makes files or directories accessible to unauthorized actors, even though they should not be. |