← WordPress Vulnerabilities
WordPress security by component

Magic Import Document Extractor

Magic Import Document Extractor is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Feb 04, 2026; the highest CVE/CNA score is 5.3.

Plugin slug: magic-import-document-extractor

CVE-2025-15508: Magic Import Document Extractor: Sensitive information exposure

Magic Import Document Extractor is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.

PublishedFeb 04, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 04, 2026 CVE-2025-15508
Magic Import Document Extractor: Sensitive information exposure
Magic Import Document Extractor is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVDPending
Feb 04, 2026 CVE-2025-15507
Magic Import Document Extractor: A security weakness
Magic Import Document Extractor is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending