CVE-2025-15508

The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.4 via the get_frontend_settings() function. This makes it possible for unauthenticated attackers to extract the site's magicimport.ai license key from the page source on any page containing the plugin's shortcode.
Configurations

No configuration.

History

04 Feb 2026, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-04 09:15

Updated : 2026-02-04 16:33


NVD link : CVE-2025-15508

Mitre link : CVE-2025-15508

CVE.ORG link : CVE-2025-15508


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor