Impact
The vulnerability manifests as a missing authorization check in the RealMag777 MDTF wp‑meta‑data‑filter‑and‑taxonomy‑filter WordPress plugin, which enables users who should not have access to retrieve or manipulate data managed by the plugin. Because the flaw bypasses role‑based restrictions, attackers could read, edit, or delete protected content, impacting confidentiality and integrity of the site. The weakness involves improper handling of access control levels and is classified as CWE‑862.
Affected Systems
The RealMag777 MDTF wp‑meta‑data‑filter‑and‑taxonomy‑filter plugin for WordPress is affected for all releases up to and including version 1.3.6. Users running any version in this range are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity, while the EPSS score of less than 1 percent indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread, documented attacks. Exploitation would occur over the web through the plugin’s endpoints and would require either an authenticated user with sufficient privileges or a misconfigured site that unintentionally exposes the plugin functions to unauthenticated traffic.
OpenCVE Enrichment