CVE-2025-15507: Magicimport Magic Import Document Extractor

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Magic Import Document Extractor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_sync_usage() function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to modify the plugin's license status and credit balance.

Affected products

  • Magicimport Magic Import Document Extractor: up to and including 1.0.5

Published 2026-02-04. Last modified 2026-06-17.