Reflected Cross-Site Scripting Vulnerability in MPG WordPress Plugin
CVE-2026-13726
Currently unrated
Key Information:
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2026-13726?
The MPG WordPress plugin prior to version 4.1.8 is susceptible to a reflected cross-site scripting vulnerability. Due to improper sanitization and escaping of a specific parameter, unauthenticated attackers can exploit this flaw by crafting a malicious request. When a victim interacts with this request, the attacker can execute arbitrary scripts within the user's browser context, potentially leading to theft of sensitive information or session hijacking.
Affected Version(s)
MPG 0 < 4.1.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.