CVE-2026-104402: WordPress Mindio Magic MCP plugin <= 0.5.6 - Sensitive Data Exposure vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve Embedded Sensitive Data.This issue affects Mindio Magic MCP: from n/a through 0.5.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Mindio Magic MCP pluginto a version that resolves this vulnerability.Fixed in 0.7.1
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges. Exploitation does not require user interaction and can be performed over the network.
What is the expected impact if the vulnerability is exploited?
The issue may allow retrieval of embedded sensitive data, affecting confidentiality. The supplied severity vector indicates low confidentiality impact and no integrity or availability impact.
Which plugin versions are affected?
Mindio Magic MCP versions through 0.5.6 are affected. No lower bound is specified in the available information.