SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13726

HIGH · CVSS 7.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The MPG WordPress plugin prior to version 4.1.8 is vulnerable to reflected cross-site scripting due to inadequate sanitization and escaping of user-supplied parameters. This flaw allows unauthenticated attackers to execute malicious scripts in the context of a victim's browser, potentially leading to data theft or session hijacking. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this high-severity risk.

CVE
CVE-2026-13726
Severity
HIGH
CVSS
7.1
EPSS
0.16%
WordPress

Original NVD Description

The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.