PatchSiren

MPG CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review MPG CVE published 2026-07-27

CVE-2026-13726

The MPG WordPress plugin before 4.1.8 is vulnerable to Reflected Cross-Site Scripting. This is due to the plugin not properly sanitizing and escaping a parameter before reflecting it back in the response. An unauthenticated attacker can exploit this by inducing a victim to send a crafted request, potentially leading to malicious script execution. Users of the MPG WordPress plugin, especially those with ve [truncated]