CVE-2024-10705
- EPSS 0.05%
- Veröffentlicht 26.01.2025 07:15:07
- Zuletzt bearbeitet 04.02.2025 20:08:12
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.5 via the 'mpg_download_file_by_link' function. This makes it possible for authenticated attackers, w...
CVE-2024-10672
- EPSS 0.26%
- Veröffentlicht 12.11.2024 04:15:04
- Zuletzt bearbeitet 14.11.2024 18:49:26
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the mpg_upsert_project_source_block() function in all versions up to, and including, 4.0.2. This makes ...
CVE-2024-47325
- EPSS 0.62%
- Veröffentlicht 20.10.2024 10:15:03
- Zuletzt bearbeitet 24.10.2024 14:43:29
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows SQL Injection.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.7.
CVE-2024-31301
- EPSS 0.06%
- Veröffentlicht 12.04.2024 13:15:18
- Zuletzt bearbeitet 07.02.2025 01:41:21
Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.
CVE-2024-27951
- EPSS 0.53%
- Veröffentlicht 03.04.2024 12:15:11
- Zuletzt bearbeitet 07.02.2025 16:59:17
Unrestricted Upload of File with Dangerous Type vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows Upload a Web Shell to a Web Server.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.
CVE-2024-30235
- EPSS 0.56%
- Veröffentlicht 26.03.2024 13:15:46
- Zuletzt bearbeitet 07.02.2025 16:54:26
Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.
CVE-2023-33927
- EPSS 0.44%
- Veröffentlicht 31.10.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:06:13
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple Page Generator Plugin – MPG multiple-pages-generator-by-porthas allows SQL Injection.This issue affects Multiple Page Generator P...
CVE-2023-2607
- EPSS 0.4%
- Veröffentlicht 09.06.2023 06:16:10
- Zuletzt bearbeitet 21.11.2024 07:58:55
The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to insufficient escaping on the user supplied parameter and lack of sufficien...
CVE-2023-2608
- EPSS 0.09%
- Veröffentlicht 17.05.2023 02:15:10
- Zuletzt bearbeitet 21.11.2024 07:58:55
The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to missing nonce verification on the pr...
CVE-2022-47143
- EPSS 0.09%
- Veröffentlicht 14.03.2023 09:15:13
- Zuletzt bearbeitet 21.11.2024 07:31:34
Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG plugin <= 3.3.9 versions.