The MPG plugin for WordPress, called the Multiple Page Generator Plugin, has a security vulnerability in versions up to 3.4.7. This is because the plugin does not properly protect against SQL Injection, which allows attackers with contributor-level access or higher to add their own SQL queries to the existing ones. This can lead to the extraction of sensitive information from the website’s database.