Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-02-04

CVE-2025-15508 - Magic Import Document Extractor Plugin

The Magic Import Document Extractor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.4 via the get_frontend_settings() function. This makes it possible for unauthenticated attackers to extract the site's magicimport.ai license key from the page source on any page containing the plugin's shortcode.

PLUGIN Magic Import Document Extractor

CVE-2025-15508

MEDIUM CVSS 5.3 2026-02-04
Threat Entry Updated 2026-02-04

CVE-2025-15507 - Magic Import Document Extractor Plugin

The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_sync_usage() function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to modify the plugin's license status and credit balance.

PLUGIN Magic Import Document Extractor

CVE-2025-15507

MEDIUM CVSS 5.3 2026-02-04
Scroll to top