Vulnerabilities > Themeisle > Multiple Page Generator > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-05-17 CVE-2023-2608 Cross-Site Request Forgery (CSRF) vulnerability in Themeisle multiple Page Generator
The Multiple Page Generator Plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to missing nonce verification on the projects_list function and insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
themeisle CWE-352
4.3