Access Control Flaw in RealMag777's MDTF Plugin for WordPress
CVE-2025-49907

4.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
22 October 2025

What is CVE-2025-49907?

A missing authorization vulnerability in RealMag777's MDTF (wp-meta-data-filter-and-taxonomy-filter) plugin for WordPress could allow attackers to exploit improperly configured access controls, potentially granting unauthorized access to sensitive areas of the application. This issue affects versions from n/a through 1.3.3.9, highlighting the need for users to audit and mitigate security settings effectively.

Affected Version(s)

MDTF <= n/a

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Legion Hunter (Patchstack Alliance)
.