CVE-2026-104953 PUBLISHED

MPG < 4.2.3 - Editor+ SQLi via Project Import

Assigner: WPScan
Reserved: 02.10.2026 Published: 07.10.2026 Updated: 07.10.2026

The MPG WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform SQL injection attacks and read sensitive data such as password hashes.

Product Status

Vendor Unknown
Product MPG
Versions Default: unaffected
  • affected from 0 to 4.2.3 (excl.)

Credits

  • ieuns finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE