What the vulnerability does
01Description
Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.
Explanation of Vulnerability in Simple Terms
The Multiple Page Generator Plugin for WordPress contains an authorization flaw that allows authenticated users with low privileges to access sensitive information they should not be able to view. An attacker with a basic user account can read data that is restricted to higher-privilege roles. The vulnerability affects versions up to 3.4.0 and requires a valid WordPress login to exploit.
What an attacker can do
Read sensitive data restricted to higher-privilege user roles.
Potential impact on your site
Unauthorized information disclosure to low-privilege users; data confidentiality compromised.
Conditions required to exploit
Valid WordPress user account with low privileges (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities