Input validation vulnerability in Multiple Page Generator Plugin – MPG 3.3.17

The Multiple Page Generator Plugin for WordPress is vulnerable to a type of cyber attack called SQL Injection. This vulnerability exists in versions up to and including 3.3.17. Unprivileged users with administrator privileges can use this vulnerability to extract sensitive information from the WordPress database. This is caused by the user-supplied parameters not being properly escaped and the existing SQL query not being sufficiently prepared.

Detected in:

Multiple Page Generator Plugin – MPG fixed vulnerable versions: >= * <= 3.3.17

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.