Junglewise Threat Intelligence

CVE-2026-54843: PluginUs.Net MDTF unauthenticated SQL injection

CVE-2026-54843 · Severity: critical · CVSS 9.3 · Published 2026-06-25

Vendors: PluginUs.Net.

Executive brief

The MDTF (WordPress Meta Data and Taxonomy Filter) plugin, used for advanced searching and filtering on WordPress websites, contains a critical security flaw. An unauthenticated attacker can exploit this vulnerability to interact directly with the website's database. This could lead to the theft of sensitive customer data, exposure of administrative credentials, or disruption of site operations.

Technical details

A SQL injection vulnerability exists in the MDTF (WordPress Meta Data and Taxonomy Filter) plugin due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows an unauthenticated remote attacker to execute arbitrary SQL queries against the backend database via specially crafted network requests. This can result in unauthorized data retrieval, including sensitive user information and configuration details. The vulnerability is present in versions 1.3.7 and earlier; it was addressed in version 1.3.8.

Affected products

  • PluginUs.Net MDTF (WordPress Meta Data and Taxonomy Filter) <= 1.3.7

Timeline

  • 2026-05-19: other: Vulnerability reported by researcher Roll
  • 2026-06-18: advisory: Patchstack published advisory
  • 2026-06-25: disclosed: CVE published to NVD
  • 2026-06-25: patched: Version 1.3.8 released to address the issue

References