PricingCase studies Login Start trial
Plugin Icon

MPG

Themeisle

Developer

4.1.4

Latest version

2,000

Installations

No date

Last updated

WordPress Plugin
Active VDP
Report vulnerability
    VulnerabilitiesSecurity PolicySecurity Contributors

Vulnerability history

0 present
12 fixed
3 Mitigation rules
  • Authenticated (Editor+) Server-Side Request Forgery via fileUrl vulnerability
    <= 4.0.5
    Jan 27, 2025
  • Authenticated (Editor+) Directory Traversal to Limited File Deletion vulnerability
    <= 4.0.2
    Nov 12, 2024
  • Missing Authorization vulnerability
    <= 4.0.1
    Oct 31, 2024
  • SQL Injection vulnerability
    <= 3.4.7
    Sep 25, 2024
  • Cross Site Request Forgery (CSRF) vulnerability
    <= 3.4.0
    Apr 5, 2024
  • Broken Access Control vulnerability
    <= 3.4.0
    Mar 26, 2024
  • Remote Code Execution (RCE) vulnerability
    <= 3.4.0
    Mar 13, 2024
  • Reflected Cross Site Scripting (XSS) vulnerability
    <= 2.8.12
    Jul 19, 2023
  • SQL Injection vulnerability
    <= 3.3.19
    May 23, 2023
  • Authenticated (Administrator+) SQL Injection vulnerability
    <= 3.3.17
    May 16, 2023
  • Cross-Site Request Forgery vulnerability
    <= 3.3.17
    May 16, 2023
  • Cross Site Request Forgery (CSRF)
    <= 3.3.9
    Feb 20, 2023

Vulnerability mitigation

  • Pricing
  • Application security (SCA)
  • RapidMitigate New
  • Threat Intelligence (API)
  • VS Monarx
  • VS Imunify360
  • VS Wordfence
  • Documentation
  • Service status
  • Log in

Code security

  • Managed VDP New
  • Active VDP directory 1,098
  • Security auditing
  • Compliance (CRA) New
  • Log in New

Bug bounty

  • Bug bounty
  • Leaderboard
  • Guidelines
  • Learn New
  • Report
  • Discord
  • Log in New

Use cases

  • Web developers
  • Webhosts New
  • Software vendors
  • WordPress
  • WooCommerce

Resources

  • Vulnerability database
  • Whitepaper 2025 New
  • Articles
  • Case studies New
  • Webinars New
  • Vulnerability statistics

Patchstack

  • About
  • Careers
  • Merch store
  • Media kit
  • LinkedIn
  • Facebook
  • X
© 2026 Patchstack
DPA
Privacy Policy
Accessibility
Terms & Conditions
EU Flag