{"id":"CVE-2026-104953","title":"The MPG  WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform SQL injection attacks and read sensiti…","summary":"The MPG  WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform SQL injection attacks and read sensiti…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-89"],"product":"MPG","affected":["MPG < 4.2.3"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T14:52:43.420","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104953","references":[{"url":"https://wpscan.com/vulnerability/e0b17720-b055-4d90-b0fa-68911274dafa/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-07T09:54:14.246399Z"},"ingestedAt":"2026-10-07T08:20:03.940Z","epss":0.00231,"epssPercentile":0.12745,"slug":"CVE-2026-104953","body":"## Overview\n\nThe MPG  WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform SQL injection attacks and read sensitive data such as password hashes.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":217387,"id":"CVE-2026-104953","ts":1791368786207,"field":"cvss","old":null,"new":"6.8"},{"seq":217386,"id":"CVE-2026-104953","ts":1791368786207,"field":"severity","old":"none","new":"medium"}]}