What the vulnerability does
01Description
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the mpg_upsert_project_source_block() function in all versions up to, and including, 4.0.2. This makes it possible for authenticated attackers, with editor-level access and above, to delete limited files on the server.
Explanation of Vulnerability in Simple Terms
02Summary
The Multiple Page Generator Plugin for WordPress contains an integrity issue affecting versions up to 4.0.2. An authenticated administrator with high privileges can modify plugin behavior or settings in unintended ways. The vulnerability has low severity and requires administrator-level access to exploit. Update to a version newer than 4.0.2 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Modify plugin settings or data in ways not intended by the plugin design.
Potential impact on your site
04Site Impact
A malicious admin account could alter plugin configuration or stored data, potentially affecting site functionality.
Conditions required to exploit
05Prerequisites
Attacker must have administrator-level access to the WordPress site.
Key dates
06Disclosure timeline
November 12, 2024
CVE published
April 8, 2026
Record updated