CVE WATCH / VULNERABILITY DETAIL
CVE-2026-104953
MEDIUMCVSS 6.8NVD feed
Published 7 October 2026 · tracked since 8 October 2026
Description
The MPG WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform SQL injection attacks and read sensitive data such as password hashes.
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107204 CRITICAL 9.8
- CVE-2026-106559 MEDIUM 6.3
- CVE-2026-106560 HIGH 7.1
- CVE-2026-106561 MEDIUM 5
- CVE-2026-106563 MEDIUM 5.3
- CVE-2026-106558 HIGH 8.8
- CVE-2026-106510 HIGH 7.7
- CVE-2026-106556 HIGH 7.7
- CVE-2025-70521 CRITICAL 9.8
- CVE-2025-70518 CRITICAL 10