Description
The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and including, 4.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is only exploitable when the [mpg_spintax] shortcode is rendered in site-wide content such as a footer or template part, as the vulnerable code path is only reached when the shortcode is active on the requested page.
Published: 2026-09-12
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via SQL Injection
Action: Update Plugin
AI Analysis

Impact

The MPG – Multiple Page Generator plugin for WordPress contains a generic SQL Injection flaw where the code builds database queries from user input in the URL path without proper escaping or prepared statements. An authenticated attacker with subscriber-level access or higher can append arbitrary SQL clauses to existing queries, allowing the extraction of sensitive data from the database. The vulnerability is active only when the [mpg_spintax] shortcode is rendered in page‑wide content such as footers or template parts. It is identified as CWE‑89, a classic injection weakness.

Affected Systems

Any WordPress site that runs the themeisle MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin with a version up to and including 4.2.1 is affected. The flaw is triggered only when the [mpg_spintax] shortcode is rendered in site‑wide content such as footers or template parts. Users with subscriber‑level access or higher can exploit the vulnerability by accessing specific URLs on the site.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score is less than 1 % reflecting a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated user with subscriber‑level renders the [mpg_spintax] shortcode in site‑wide content. By crafting a URL that injects additional SQL clauses, the attacker can read sensitive database information. Because the flaw depends on privileged access and specific page rendering, the potential for information disclosure warrants prompt remediation.

Generated by OpenCVE AI on September 15, 2026 at 18:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MPG plugin to the latest version that removes the unsanitized URL handling in the HookController and SpintaxController modules
  • If an upgrade is not immediately possible, disable the [mpg_spintax] shortcode in all site‑wide templates and footers until the patch is applied
  • Configure the WordPress URL parameters to prevent SQL injection before reaching the MPG code

Generated by OpenCVE AI on September 15, 2026 at 18:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Themeisle
Themeisle mpg – Multiple Page Generator, Bulk Landing Pages & Programmatic Seo
Wordpress
Wordpress wordpress
Vendors & Products Themeisle
Themeisle mpg – Multiple Page Generator, Bulk Landing Pages & Programmatic Seo
Wordpress
Wordpress wordpress

Sat, 12 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and including, 4.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is only exploitable when the [mpg_spintax] shortcode is rendered in site-wide content such as a footer or template part, as the vulnerable code path is only reached when the shortcode is active on the requested page.
Title MPG <= 4.2.1 - Unauthenticated SQL Injection via URL Path
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Themeisle Mpg – Multiple Page Generator, Bulk Landing Pages & Programmatic Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-14T18:30:17.856Z

Reserved: 2026-09-03T12:52:53.344Z

Link: CVE-2026-85198

cve-icon Vulnrichment

Updated: 2026-09-14T18:30:14.317Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T08:16:24.670

Modified: 2026-09-14T19:17:51.337

Link: CVE-2026-85198

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:45:18Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')