What the vulnerability does
01Description
Missing Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.
Explanation of Vulnerability in Simple Terms
The WordPress Meta Data and Taxonomies Filter plugin through version 1.3.3 lacks proper authorization checks on certain administrative functions. A logged-in user with low privileges can modify data they should not have access to. The vulnerability requires an active WordPress account but no special interaction from the victim.
What an attacker can do
Modify metadata or taxonomy data without proper permission checks.
Potential impact on your site
Unauthorized users can alter site metadata and taxonomy settings, potentially corrupting content organization or site structure.
Conditions required to exploit
Attacker must have a low-privilege WordPress account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities