Vulnerability  ·  2026-10-05

Mindio Magic MCP WordPress plugin: sensitive data exposure (embedded secrets retrievable)

VulnerabilityMedium impactGlobalCVE-2026-104402
NVD published CVE-2026-104402 (CVSS 4.3) on 2026-10-04 via Patchstack for a sensitive-data exposure in the Mindio Magic MCP WordPress plugin through 0.5.6, fixed in 0.7.1.
A WordPress MCP connector that leaks the secrets used to talk to an MCP model/agent service undermines exactly the credential handling MCP integrations need. Niche, low blast radius but relevant to the MCP ecosystem, keep as precision CVE.
CWE-201 insertion of sensitive information into sent data: client-controlled requests cause the plugin to expose embedded sensitive data (MCP/API credentials), leaking them to an authenticated requester.
Mindio Magic MCP WordPress plugin <= 0.5.6 (fixed in 0.7.1)
Update Mindio Magic MCP to 0.7.1 or later. Advisory: https://patchstack.com/database/wordpress/plugin/mindio-magic-mcp/vulnerability/wordpress-mindio-magic-mcp-plugin-0-5-6-sensitive-data-exposure-vulnerability
NVD CVE-2026-104402Patchstack advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →