Local Magic
Local Magic has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; none of them are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 1 of the records (50%). Other recurring categories include SQL Injection.
None of the 2 issues recorded for Local Magic have a published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by LVT-tholv2k. Local Magic is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-32636Local Magic <= 2.6.0 - Unauthenticated SQL Injection
Read the full analysisVulnerability Records

Local Magic
Author
matthewrubin
The Local Magic© WordPress plugin extends the functionality of the SaaS Local Magic© to WordPress so that the local magic can be displayed on the WordPress website. The plugin is for customers of Local Magic© that have an active subscription with the company. More information We used this “https://localmagic.reviewmanager.app” server to validate “Local Magic” Plugin license/ Key and please visit the plugin website at https://www.mrmarketingres.com/local-magic/ for detail information about “Local Magic” plugin. Please see our Privacy and Policy at https://www.mrmarketingres.com/privacy-policy/ Supporting future development Collect Local Magic via our App as per Keywords and City Publish local magic to your website with our WordPress plugin and website local magic widget
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C