CVE-2026-32584
Received Received - Intake

Sensitive Data Exposure in Smart One Click Setup

Vulnerability report for CVE-2026-32584, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Patchstack

Description

Insertion of Sensitive Information Into Sent Data vulnerability in Chiranjit Hazarika Smart One Click Setup – Complete Demo Import & Export smart-one-click-setup allows Retrieve Embedded Sensitive Data.This issue affects Smart One Click Setup – Complete Demo Import & Export: from n/a through 1.4.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
chiranjit_hazarika smart_one_click_setup to 1.4.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves sensitive data exposure in the WordPress plugin Smart One Click Setup – Complete Demo Import & Export versions up to 1.4.3. Unauthorized parties can access private information such as passwords, emails, or payment details due to improper handling of embedded data.

Detection Guidance

Check if the WordPress plugin 'Smart One Click Setup – Complete Demo Import & Export' version 1.4.3 or lower is installed. Review server logs for unauthorized access attempts to sensitive data like passwords or payment details.

Impact Analysis

Attackers could steal sensitive information like passwords or payment details, leading to identity theft, financial loss, or unauthorized account access. The impact is considered low severity but still poses risks to user privacy and security.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA due to unauthorized access to personal or sensitive health data. Organizations may face legal penalties, fines, or reputational damage for failing to protect such data.

Mitigation Strategies

Update the plugin to the latest version if available. If no update exists, consider disabling the plugin or seeking assistance from your hosting provider or web developer to remove or replace it.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-32584. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart