← WordPress Vulnerabilities
WordPress security by component

MPG

MPG is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.1.

Plugin slug: mpg

CVE-2026-13726: MPG request input permits unauthenticated reflected XSS

MPG before 4.1.8 reflects attacker-controlled request input without sufficient sanitization and output escaping. An unauthenticated attacker can construct a URL or request that executes script in the affected site's origin when a victim opens it. The CNA record does not disclose the endpoint, action, parameter or rendering function.

PublishedJul 27, 2026
Known safe version4.1.8
Safe version
Jul 27, 2026 CVE-2026-13726
MPG request input permits unauthenticated reflected XSS
MPG before 4.1.8 reflects attacker-controlled request input without sufficient sanitization and output escaping. An unauthenticated attacker can construct a URL or request that executes script in the affected site's origin when a victim opens it. The CNA record does not disclose the endpoint, action, parameter or rendering function.
4.1.8
CVE7.1
NVDPending