WordPress security by component
MPG
Plugin description
MPG is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.1.
Plugin slug:
mpgLatest vulnerability
CVE-2026-13726: MPG request input permits unauthenticated reflected XSS
MPG before 4.1.8 reflects attacker-controlled request input without sufficient sanitization and output escaping. An unauthenticated attacker can construct a URL or request that executes script in the affected site's origin when a victim opens it. The CNA record does not disclose the endpoint, action, parameter or rendering function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-13726
MPG request input permits unauthenticated reflected XSS
MPG before 4.1.8 reflects attacker-controlled request input without sufficient sanitization and output escaping. An unauthenticated attacker can construct a URL or request that executes script in the affected site's origin when a victim opens it. The CNA record does not disclose the endpoint, action, parameter or rendering function.
|
4.1.8 |
CVE7.1
NVDPending
|