PT-2025-1604 · WordPress · Multiple Page Generator Plugin
Arkadiusz Hydzik
·
Published
2025-01-26
·
Updated
2025-01-26
·
CVE-2024-10705
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Multiple Page Generator Plugin – MPG plugin for WordPress versions up to, and including, 4.0.5
Description
The issue allows authenticated attackers, with editor-level access and above, to make web requests to arbitrary locations originating from the web application via the
mpg download file by link function. This can be used to query and modify information from internal services.Recommendations
For versions up to, and including, 4.0.5, consider disabling the
mpg download file by link function as a temporary workaround until a patch is available. Restrict access to the plugin's functionality to minimize the risk of exploitation, ensuring only necessary personnel have editor-level access or above.Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Multiple Page Generator Plugin