PT-2026-63492 · WordPress · Mpg

CVE-2026-63676

·

Published

2026-07-21

·

Updated

2026-08-27

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions MPG WordPress plugin versions prior to 4.1.8
Description An issue exists where the software fails to sanitize and escape parameters before reflecting them in the response. This allows an unauthenticated attacker to execute reflected cross-site scripting (XSS) against a victim who is induced to send a crafted request.
Recommendations Update MPG WordPress plugin to version 4.1.8 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-63676
ECHO-A943-8F53-50DF
OESA-2026-3237
OESA-2026-3238
OESA-2026-3239
OESA-2026-3240
OESA-2026-3406
OPENSUSE-SU-2026:11321-1

Affected Products

Mpg