← back
CVE-2026-103293mediumCWE-22

MPG < 4.2.3 - Editor+ Arbitrary File Read via Project Import

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 6.8epss 0.4%
exploitation probability
0.4%top 73% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The MPG WordPress plugin before 4.2.3 does not validate that the dataset source supplied when importing a project is a remote URL before treating it as a local filesystem path and copying that file into a publicly accessible uploads folder. This makes it possible for users with the Editor role and above to read the contents of arbitrary files on the server, with the copied file then retrievable by unauthenticated visitors.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Affected products
Unknown · MPG
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.