CVE-2025-49907

8.2

RealMag777 · MDTF (wp-meta-data-filter-and-taxonomy-filter)

A missing authorization vulnerability in the MDTF WordPress plugin allows authenticated users to exploit incorrectly configured access control security levels.

Executive summary

A missing authorization vulnerability in the RealMag777 MDTF plugin for WordPress exposes systems to unauthorized access control exploitation by authenticated users.

Vulnerability

This is a CWE-862 missing authorization vulnerability where the plugin fails to properly validate the privileges of an authenticated user, allowing them to perform actions beyond their intended scope.

Business impact

The vulnerability carries a CVSS score of 8.2, reflecting a high potential for unauthorized actions within the WordPress environment. Successful exploitation could lead to unauthorized configuration changes, data integrity issues, or service disruption, potentially resulting in operational downtime and a loss of administrative control over the affected site.

Remediation

Immediate Action: Since a specific patch version is currently unknown, administrators should monitor the official Patchstack database and the WordPress plugin repository for a security release and apply it immediately upon availability.

Proactive Monitoring: Review web server access logs for anomalous activity originating from standard user accounts, specifically monitoring for requests to sensitive administrative endpoints or plugin-specific settings.

Compensating Controls: Implement a Web Application Firewall (WAF) to filter suspicious requests and restrict access to administrative interfaces to known, trusted IP addresses to limit the impact of broken access control.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score, this vulnerability poses a significant risk to site integrity. Security teams should prioritize identifying all instances of the MDTF plugin in their environment and maintain a heightened state of readiness to update the software as soon as the vendor provides a remediation path.

More RealMag777 CVEs

Sources

Originally found and disclosed by Legion Hunter | Patchstack Bug Bounty Program, per the CVE Program record.