CVE-2026-104953
Description
AI Translation Available
The MPG WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform SQL injection attacks and read sensitive data such as password hashes.
https://wpscan.com/vulnerability/e0b17720-b055-4d90-b0fa-68911274dafa/