Impact
The MPG – Multiple Page Generator plugin for WordPress contains a generic SQL Injection flaw where the code builds database queries from user input in the URL path without proper escaping or prepared statements. An authenticated attacker with subscriber-level access or higher can append arbitrary SQL clauses to existing queries, allowing the extraction of sensitive data from the database. The vulnerability is active only when the [mpg_spintax] shortcode is rendered in page‑wide content such as footers or template parts. It is identified as CWE‑89, a classic injection weakness.
Affected Systems
Any WordPress site that runs the themeisle MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin with a version up to and including 4.2.1 is affected. The flaw is triggered only when the [mpg_spintax] shortcode is rendered in site‑wide content such as footers or template parts. Users with subscriber‑level access or higher can exploit the vulnerability by accessing specific URLs on the site.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is less than 1 % reflecting a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated user with subscriber‑level renders the [mpg_spintax] shortcode in site‑wide content. By crafting a URL that injects additional SQL clauses, the attacker can read sensitive database information. Because the flaw depends on privileged access and specific page rendering, the potential for information disclosure warrants prompt remediation.
OpenCVE Enrichment