The Multiple Page Generator Plugin for WordPress is vulnerable to a type of cyber attack called SQL Injection. This vulnerability exists in versions up to and including 3.3.17. Unprivileged users with administrator privileges can use this vulnerability to extract sensitive information from the WordPress database. This is caused by the user-supplied parameters not being properly escaped and the existing SQL query not being sufficiently prepared.