What happened
NVD published CVE-2026-104402 (CVSS 4.3) on 2026-10-04 via Patchstack for a sensitive-data exposure in the Mindio Magic MCP WordPress plugin through 0.5.6, fixed in 0.7.1.
Why it matters
A WordPress MCP connector that leaks the secrets used to talk to an MCP model/agent service undermines exactly the credential handling MCP integrations need. Niche, low blast radius but relevant to the MCP ecosystem, keep as precision CVE.
Attack vector
CWE-201 insertion of sensitive information into sent data: client-controlled requests cause the plugin to expose embedded sensitive data (MCP/API credentials), leaking them to an authenticated requester.
Affected systems
Mindio Magic MCP WordPress plugin <= 0.5.6 (fixed in 0.7.1)
Mitigation
Update Mindio Magic MCP to 0.7.1 or later. Advisory: https://patchstack.com/database/wordpress/plugin/mindio-magic-mcp/vulnerability/wordpress-mindio-magic-mcp-plugin-0-5-6-sensitive-data-exposure-vulnerability