Sceawere

Vulnerability Detail

CVE-2026-103293UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MPG Plugin Arbitrary File Read

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
13h ago
Vendor
Unknown
Product
MPG
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The MPG WordPress plugin before 4.2.3 does not validate that the dataset source supplied when importing a project is a remote URL before treating it as a local filesystem path and copying that file into a publicly accessible uploads folder. This makes it possible for users with the Editor role and above to read the contents of arbitrary files on the server, with the copied file then retrievable by unauthenticated visitors.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-10-03T06:16:40.440Z",
  "pubdate": "2026-10-03T06:16:40.440Z",
  "executiveSummary": "The MPG WordPress plugin, in versions prior to 4.2.3, contains a critical vulnerability involving improper validation of dataset source inputs during project imports. This flaw allows an authenticated attacker with an Editor role or higher to trigger an Arbitrary File Read vulnerability. By providing a local filesystem path instead of an expected remote URL, the application mistakenly processes the input as a valid source and copies the targeted file into a publicly accessible directory within the WordPress uploads folder. This oversight effectively bypasses access control mechanisms, exposing sensitive server-side files to unauthenticated external actors. The vulnerability poses a significant risk to confidentiality, as attackers can exfiltrate configuration files, database credentials, or system sensitive data by manipulating the import function. Exploitation requires authenticated access to the WordPress dashboard with at least Editor-level privileges, but the resulting impact is severe due to the ability to disclose arbitrary filesystem contents publicly.",
  "technicalDetails": "The vulnerability resides in the project import mechanism of the MPG plugin, specifically within the handling of dataset source parameters. The root cause is a failure to implement server-side validation or sanitization to ensure the provided dataset source is a legitimate remote URL. Because the plugin does not verify the protocol or the nature of the input string, it incorrectly treats local filesystem paths as valid resources.\nThe exploitation flow initiates when an attacker with Editor or Administrator privileges interacts with the plugin’s project import interface. By submitting a crafted request where the dataset source parameter points to a sensitive local file—such as wp-config.php, system configuration files, or other sensitive documents—the application logic executes a file retrieval operation. Instead of performing an HTTP GET request to a remote resource, the vulnerable code consumes the path provided and utilizes internal file handling functions to copy the target resource from the server's local storage.\nDuring this process, the plugin copies the contents of the specified local file into a directory within the publicly accessible WordPress 'uploads' folder. Once the file is moved to this public web space, the protection mechanism is effectively bypassed. The final stage of the attack involves the attacker accessing the moved file via a standard browser request, as the file is now served by the web server as static content. Since the file is placed in a public directory, this access does not require further authentication.\nThis vulnerability is particularly dangerous because it allows an attacker to pivot from an authorized Editor role to unauthorized system information disclosure. The ability to read arbitrary files allows for the extraction of sensitive environment variables, database credentials, or private keys, which may facilitate further privilege escalation or complete system compromise. The flaw demonstrates a lack of 'trust boundary' enforcement when processing user-supplied inputs destined for file manipulation operations.\nThe vulnerability affects all versions of the MPG plugin prior to 4.2.3. No specific network-level exploits are required beyond access to the WordPress administration interface, making this a high-impact application-layer flaw."
}
CVE-2026-103293: MPG Plugin Arbitrary File Read (MEDIUM Severity, CVSS: 6.8) | Sceawere