CVE-2026-104953: Unknown Mpg

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The MPG WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform SQL injection attacks and read sensitive data such as password hashes.

Affected products

  • Unknown Mpg: before 4.2.3 (fixed in 4.2.3)

Published 2026-10-07. Last modified 2026-10-07.