VYPR

MPG

by WordPress

CVEs (2)

  • CVE-2024-10705MedJan 26, 2025
    risk 0.28cvss 5.4epss 0.00

    The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.5 via the 'mpg_download_file_by_link' function. This makes it possible for authenticated attackers, with editor-level access and…

  • CVE-2026-13726HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.