Description
Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve Embedded Sensitive Data.This issue affects Mindio Magic MCP: from n/a through 0.5.6.
Published: 2026-10-04
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an insertion of sensitive information into data transmitted by the Mindio Magic MCP WordPress plugin, which allows an attacker to retrieve embedded sensitive data. This flaw is based on improper handling of confidential data and is classified as CWE-201, leading to a confidentiality compromise if exploited.

Affected Systems

The affected product is the WordPress Mindio Magic MCP plugin from farvisun, versions up to and including 0.5.6. The vendor recommends updating to version 0.7.1 or later to remediate the issue.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is normal use of the plugin in a WordPress site; an attacker who can load the plugin can extract sensitive information embedded in the plugin’s data outputs.

Generated by OpenCVE AI on October 4, 2026 at 17:51 UTC.

Remediation

Vendor Solution

Update the WordPress Mindio Magic MCP plugin to the latest available version (at least 0.7.1).


OpenCVE Recommended Actions

  • Update the WordPress Mindio Magic MCP plugin to version 0.7.1 or later, the officially recommended fix.
  • If an update cannot be applied immediately, disable the plugin or remove it from active use until a patch is available to prevent data exposure.
  • Review any custom code that interacts with the plugin’s data outputs and ensure that no sensitive metadata is included in responses; if necessary, remove such data or apply stricter access controls to the plugin’s endpoints.

Generated by OpenCVE AI on October 4, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve Embedded Sensitive Data.This issue affects Mindio Magic MCP: from n/a through 0.5.6.
Title WordPress Mindio Magic MCP plugin <= 0.5.6 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-04T15:08:43.541Z

Reserved: 2026-10-02T00:22:13.105Z

Link: CVE-2026-104402

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T16:16:28.587

Modified: 2026-10-04T16:16:28.587

Link: CVE-2026-104402

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T18:00:15Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data