WordPress Plugin Vulnerabilities

MPG < 4.2.3 - Editor+ SQLi via Project Import

Description

The plugin does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform SQL injection attacks and read sensitive data such as password hashes.

Proof of Concept

Affects Plugins

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Original Researcher
ieuns
Submitter
ieuns
Verified
Yes

Timeline

Publicly Published
2026-10-05 (about 2 days ago)
Added
2026-10-05 (about 1 day ago)
Last Updated
2026-10-05 (about 1 day ago)

Other