Junglewise Threat Intelligence

CVE-2026-13726: Porthas MPG reflected XSS via mpg_shortcode

CVE-2026-13726 · Severity: info · CVSS 7.1 · Published 2026-07-27

Executive brief

The Multiple Page Generator (MPG) plugin for WordPress, which helps site owners create large numbers of landing pages, contains a security flaw that allows for reflected cross-site scripting. An attacker can trick a user into clicking a malicious link, which then executes unauthorized code in the user's browser. This could lead to the theft of login cookies, unauthorized actions on the website, or the redirection of visitors to malicious sites.

Technical details

The Multiple Page Generator (MPG) plugin for WordPress fails to properly sanitize and escape the 'mpg_shortcode' parameter before reflecting it back in the HTTP response. This vulnerability allows an unauthenticated remote attacker to perform Reflected Cross-Site Scripting (XSS) by inducing a victim to visit a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions if the victim is an authenticated administrator. The issue is fixed in version 4.1.8.

Affected products

  • Porthas Multiple Page Generator (MPG) < 4.1.8

Timeline

  • 2026-07-06: disclosed: Initial public disclosure by WPScan
  • 2026-07-27: advisory: NVD publication date

References