Magic Export and Import WordPress Plugin Unauthenticated Sensitive Data Disclosure Vulnerability

Vulnerability

A vulnerability exists in the Magic Export & Import WordPress plugin in versions prior to 1.2.0. The plugin improperly stores exported CSV files in a publicly accessible directory, allowing any visitor to access and potentially leak sensitive user information. This issue arises because the exported data can be retrieved from a predictable URL pattern, exposing personal information without authentication.

Impact

Exploitation of this vulnerability leads to unauthorized access to sensitive user information, which could be misused or disclosed without consent.

Reproduction

To reproduce this vulnerability, request the exported CSV file from the publicly accessible export directory of the Magic Export & Import WordPress plugin. The file can be accessed via a predictable URL that includes the domain and the export directory path. This URL pattern allows unauthenticated users to download the exported data, which may contain sensitive personal information.

Remediation

Users are advised to update the Magic Export & Import WordPress plugin to version 1.2.0 or later, where this vulnerability has been fixed.

Added: May 4, 2026, 7:26 AM
Updated: May 4, 2026, 7:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
7.5
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.