CVE-2026-103293

CVE-2026-103293 published: The MPG WordPress plugin before 4.2.3 does not validate that the dataset source supplied when importing a project is a remote URL before treating it as a local filesystem path and copying that file into a publicly accessible uploads folder. This makes it p...

View full NVD advisory → ← Back to CVE watch