CVE-2026-85198
- EPSS 0.29%
- Veröffentlicht 12.09.2026 07:39:14
- Zuletzt bearbeitet 14.09.2026 19:17:51
The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and including, 4.2.1 due to insufficient escaping on the user supplied parameter ...
CVE-2024-10705
- EPSS 0.34%
- Veröffentlicht 26.01.2025 07:15:07
- Zuletzt bearbeitet 04.02.2025 20:08:12
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.5 via the 'mpg_download_file_by_link' function. This makes it possible for authenticated attackers, w...
CVE-2024-10672
- EPSS 0.5%
- Veröffentlicht 12.11.2024 04:15:04
- Zuletzt bearbeitet 14.11.2024 18:49:26
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the mpg_upsert_project_source_block() function in all versions up to, and including, 4.0.2. This makes ...
CVE-2024-47325
- EPSS 0.47%
- Veröffentlicht 20.10.2024 10:15:03
- Zuletzt bearbeitet 23.04.2026 15:19:10
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle MPG multiple-pages-generator-by-porthas allows SQL Injection.This issue affects MPG: from n/a through <= 3.4.7.
CVE-2024-31301
- EPSS 0.22%
- Veröffentlicht 12.04.2024 13:15:18
- Zuletzt bearbeitet 28.04.2026 19:24:22
Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.
CVE-2024-27951
- EPSS 0.6%
- Veröffentlicht 03.04.2024 12:15:11
- Zuletzt bearbeitet 28.04.2026 19:23:34
Unrestricted Upload of File with Dangerous Type vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows Upload a Web Shell to a Web Server.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.
CVE-2024-30235
- EPSS 0.44%
- Veröffentlicht 26.03.2024 13:15:46
- Zuletzt bearbeitet 28.04.2026 19:23:58
Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.
CVE-2023-33927
- EPSS 0.68%
- Veröffentlicht 31.10.2023 15:15:08
- Zuletzt bearbeitet 28.04.2026 19:20:38
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple Page Generator Plugin – MPG multiple-pages-generator-by-porthas allows SQL Injection.This issue affects Multiple Page Generator P...
CVE-2023-2607
- EPSS 0.84%
- Veröffentlicht 09.06.2023 06:16:10
- Zuletzt bearbeitet 08.04.2026 17:16:56
The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to insufficient escaping on the user supplied parameter and lack of sufficien...
CVE-2023-2608
- EPSS 0.36%
- Veröffentlicht 17.05.2023 02:15:10
- Zuletzt bearbeitet 08.04.2026 19:18:17
The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to missing nonce verification on the pr...