CVE-2025-62964: WordPress MDTF plugin <= 1.3.6 - Broken Access Control vulnerability
Published Oct 27, 2025
·Updated
Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MDTF: from n/a through <= 1.3.6.
Affected Software
1 affected component
RealMag777 wp-meta-data-filter-and-taxonomy-filter (MDTF)<=1.3.6
Event History
Oct 27, 2025
CVE Published
via MITRE·01:34 AM
Data Sourced
via MITRE·01:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62964?
CVE-2025-62964 is classified as a high severity vulnerability due to missing authorization leading to incorrect access control.
2
How do I fix CVE-2025-62964?
To fix CVE-2025-62964, you should update the RealMag777 MDTF plugin to version 1.3.5 or later.
3
What is affected by CVE-2025-62964?
CVE-2025-62964 affects RealMag777 MDTF versions up to and including 1.3.4.
4
What type of vulnerability is CVE-2025-62964?
CVE-2025-62964 is a missing authorization vulnerability that allows exploitation of incorrectly configured access control.
5
Who is the vendor of CVE-2025-62964?
The vendor of CVE-2025-62964 is RealMag777, associated with the MDTF plugin.