CyberRota Analysis
AI-GeneratedThe MPG WordPress plugin prior to version 4.1.8 is vulnerable to reflected cross-site scripting due to inadequate sanitization and escaping of user-supplied parameters. This flaw allows unauthenticated attackers to execute malicious scripts in the context of a victim's browser, potentially leading to data theft or session hijacking. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this high-severity risk.
Original NVD Description
The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.