WordPress Multiple Page Generator Plugin – MPG Plugin <= 3.3.19 is vulnerable to SQL Injection
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.6epss 0.7%
exploitation probability
0.7%top 51% of all CVEs
observed exploitation
nono source reports it
In short
The WordPress MPG plugin up to version 3.3.19 has a flaw that allows attackers to inject malicious SQL commands into the database. This can lead to unauthorized data access, modification, or deletion of website information.
Technical detail
The plugin fails to properly sanitize user input before constructing SQL queries, enabling unauthenticated or low-privileged attackers to inject arbitrary SQL commands. Exploitation typically requires the attacker to interact with vulnerable input fields exposed through the plugin's interface, potentially leading to information disclosure, data manipulation, or authentication bypass.
Summary generated and translated by AI from the official description.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple Page Generator Plugin – MPG multiple-pages-generator-by-porthas allows SQL Injection.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.3.19.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Affected products
Themeisle · Multiple Page Generator Plugin – MPG