Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Magic Import Document Extractor <= 1.0.4 - Unauthenticated Sensitive Information Exposure | Magic Import Document Extractor <= 1.0.6 - Unauthenticated Sensitive Information Exposure |
Wed, 04 Feb 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 04 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.4 via the get_frontend_settings() function. This makes it possible for unauthenticated attackers to extract the site's magicimport.ai license key from the page source on any page containing the plugin's shortcode. | |
| Title | Magic Import Document Extractor <= 1.0.4 - Unauthenticated Sensitive Information Exposure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:11:49.277Z
Reserved: 2026-01-11T11:26:23.395Z
Link: CVE-2025-15508
Updated: 2026-02-04T16:49:42.670Z
Status : Deferred
Published: 2026-02-04T09:15:51.547
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-15508
No data.
OpenCVE Enrichment
Updated: 2026-04-21T16:15:40Z