What is CVE-2026-13726?
CVE-2026-13726 is a Reflected Cross-Site Scripting (XSS) vulnerability in the MPG WordPress plugin versions before 4.1.8, caused by insufficient sanitisation and escaping of a parameter before reflecting it in the response. Unauthenticated attackers can exploit this by tricking a victim into sending a crafted request. The solution is to immediately update the plugin to version 4.1.8 or higher.
Azərbaycanca: CVE-2026-13726, MPG WordPress plugin-in 4.1.8-dən əvvəlki versiyalarında bir parametrin düzgün təmizlənməməsi və escape edilməməsi səbəbi ilə Reflected Cross-Site Scripting (XSS) zəifliyidir. Bu zəiflik autentifikasiya olunmamış hücumçulara, qurbanı xüsusi hazırlanmış bir sorğu göndərməyə cəlb etməklə təsir göstərə bilər. Təsirə məruz qalmamaq üçün plaqini dərhal 4.1.8 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What is CVE-2026-13726?
CVE-2026-13726 is a Reflected Cross-Site Scripting (XSS) vulnerability in the MPG WordPress plugin versions before 4.1.8, caused by a parameter not being properly sanitised and escaped.
How to protect the MPG plugin from CVE-2026-13726?
Immediately update the MPG plugin to version 4.1.8 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.