CVE-2026-32584: WordPress Smart One Click Setup – Complete Demo Import & Export plugin <= 1.4.3 - Sensitive Data Exposure vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in Chiranjit Hazarika Smart One Click Setup – Complete Demo Import & Export smart-one-click-setup allows Retrieve Embedded Sensitive Data.This issue affects Smart One Click Setup – Complete Demo Import & Export: from n/a through 1.4.3.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates that the issue is remotely exploitable over a network, requires no privileges, and does not require user interaction.
How can I determine whether my site is affected?
Check whether Chiranjit Hazarika Smart One Click Setup – Complete Demo Import & Export is installed and whether its version is 1.4.3 or earlier. The affected version range is stated as through 1.4.3, with no lower bound provided.
What is the expected security impact?
The reported impact is limited to confidentiality, with a low confidentiality impact and no reported integrity or availability impact. The specific sensitive data that may be exposed is not identified in the available information.