Sensitive Data Exposure in Chiranjit Hazarika Smart One Click Setup Plugin
CVE-2026-32584

5.3MEDIUM

What is CVE-2026-32584?

A vulnerability has been identified in the Smart One Click Setup – Complete Demo Import & Export plugin developed by Chiranjit Hazarika. This issue allows for the retrieval of embedded sensitive data that may be sent without proper safeguards. As a result, this could inadvertently expose confidential information to unauthorized parties, potentially leading to further exploitation. Users utilizing versions up to and including 1.4.3 are advised to implement the necessary security measures to mitigate risks associated with this vulnerability.

Affected Version(s)

Smart One Click Setup – Complete Demo Import &amp; Export 0 <= 1.4.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.