First published: Tue Oct 31 2023(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Multiple Page Generator Plugin – MPG multiple-pages-generator-by-porthas allows SQL Injection.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.3.19.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Themeisle Multiple Page Generator Plugin - MPG | <=3.3.19 |
Update to 3.3.20 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-33927 is a vulnerability in the WordPress Multiple Page Generator Plugin - MPG Plugin that allows SQL injection.
CVE-2023-33927 has a severity rating of critical, with a CVSS score of 9.8.
CVE-2023-33927 affects the Themeisle Multiple Page Generator Plugin version 3.3.19 and earlier.
The CWE ID for CVE-2023-33927 is 89, which represents an SQL injection vulnerability.
To fix CVE-2023-33927, it is recommended to update the Themeisle Multiple Page Generator Plugin to a version newer than 3.3.19.