CVE-2025-49907: WordPress MDTF plugin <= 1.3.3.9 - Broken Access Control vulnerability
Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MDTF: from n/a through <= 1.3.3.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49907?
CVE-2025-49907 is classified as a missing authorization vulnerability that may allow attackers to exploit incorrectly configured access control security levels.
How do I fix CVE-2025-49907?
To fix CVE-2025-49907, update the RealMag777 MDTF plugin to the latest version that resolves the access control issues.
Which versions of MDTF are affected by CVE-2025-49907?
CVE-2025-49907 affects RealMag777 MDTF versions up to and including 1.3.3.9.
What kind of attacks can CVE-2025-49907 facilitate?
CVE-2025-49907 can potentially facilitate unauthorized access to data or functionalities within the application due to weak access controls.
Who is impacted by CVE-2025-49907?
Users of the RealMag777 MDTF plugin, specifically those using versions up to 1.3.3.9, are impacted by CVE-2025-49907.