CVE-2026-104953
Received Received - Intake

SQL Injection in MPG WordPress Plugin

Vulnerability report for CVE-2026-104953, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: WPScan

Description

The MPG WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform SQL injection attacks and read sensitive data such as password hashes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown MPG 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The MPG WordPress plugin before version 4.2.3 has a SQL injection vulnerability in its Project Import feature. The plugin does not validate the structure of imported project data before using it in database queries. This allows users with Editor role or higher to inject malicious SQL code, potentially accessing sensitive data like password hashes.

Detection Guidance

Check if the MPG WordPress plugin version is 4.2.3 or below. Inspect database queries for unusual patterns or unauthorized access attempts. Review user roles with Editor access or higher for suspicious activity.

Impact Analysis

If you are a WordPress site administrator using the MPG plugin version 4.2.3 or below, attackers with Editor access or higher could exploit this to read sensitive data such as password hashes from your database. This could lead to unauthorized access or further attacks on your site.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, which may violate compliance requirements under GDPR (data protection) or HIPAA (health information privacy). Organizations could face legal penalties or reputational damage if exploited.

Mitigation Strategies

Update the MPG plugin to version 4.2.3 or later immediately. Remove or restrict Editor role access to only trusted users. Monitor database activity for unauthorized queries or data access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104953. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart