CVE-2025-54707: WordPress MDTF Plugin <= 1.3.3.7 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 MDTF allows SQL Injection. This issue affects MDTF: from n/a through 1.3.3.7.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows SQL Injection.This issue affects MDTF: from n/a through <= 1.3.3.7.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54707?
CVE-2025-54707 is a high-severity SQL Injection vulnerability that can lead to unauthorized access or data manipulation.
How do I fix CVE-2025-54707?
To fix CVE-2025-54707, upgrade the RealMag777 MDTF or WordPress MDTF Plugin to a version beyond 1.3.3.7.
What impact does CVE-2025-54707 have on affected systems?
CVE-2025-54707 can allow an attacker to execute arbitrary SQL queries, potentially compromising the database and sensitive information.
Which versions are affected by CVE-2025-54707?
CVE-2025-54707 affects RealMag777 MDTF and WordPress MDTF Plugin versions up to and including 1.3.3.7.
Is there a workaround for CVE-2025-54707?
There are no known workarounds for CVE-2025-54707; updating to the patched version is recommended for mitigation.