Impact
The MPG WordPress plugin does not verify that a dataset source supplied during project import is a remote URL. Instead, it treats any supplied source as a local filesystem path, copies the file into a publicly accessible uploads directory, and allows the copied file to be retrieved by unauthenticated visitors. Users with the Editor role or higher can therefore read the contents of any file on the server, exposing sensitive configuration, credentials, or code. This constitutes an unauthorized information disclosure flaw.
Affected Systems
Versions of the MPG plugin older than 4.2.3 are affected. The vulnerability exists in all builds preceding that release.
Risk and Exploitability
An attacker who can obtain an Editor‑level account can trigger the import to read arbitrary files. Once imported, the file is publicly accessible, providing a simple mechanism for data exposure. The CVSS score is 6.8 and the EPSS score is below 1%; the issue is not listed in the CISA KEV catalog, suggesting it has not yet been exploited in the wild. Nevertheless, the risk remains significant for sites running the vulnerable plugin versions that grant Editor or higher privileges to untrusted users.
OpenCVE Enrichment