Junglewise Threat Intelligence

CVE-2026-54845: PluginUs.Net MDTF unauthenticated local file inclusion

CVE-2026-54845 · Severity: high · CVSS 8.1 · Published 2026-06-25

Vendors: PluginUs.Net.

Executive brief

The MDTF (WP Meta Data Filter and Taxonomy Filter) plugin for WordPress is vulnerable to a security flaw that allows unauthorized users to access sensitive files on the server. By exploiting this vulnerability, an attacker could view internal configuration files, such as those containing database credentials, potentially leading to a full site takeover. This issue affects websites using version 1.3.8 or older of the plugin.

Technical details

The MDTF (WP Meta Data Filter and Taxonomy Filter) plugin for WordPress is vulnerable to Local File Inclusion (LFI) in versions up to and including 1.3.8. The vulnerability stems from improper control of filenames used in PHP include or require statements (CWE-98), allowing an unauthenticated attacker to specify local files for execution or disclosure. While the attack vector is network-based and requires no privileges, the CVSS assessment indicates high complexity, likely due to specific configuration requirements or input filtering that must be bypassed. Successful exploitation can lead to the exposure of sensitive system files or remote code execution if the attacker can upload or influence the content of a local file. A fix is available in version 1.3.9.

Affected products

  • PluginUs.Net MDTF (WP Meta Data Filter and Taxonomy Filter) <= 1.3.8

Timeline

  • 2026-06-02: other: Reported by Ossacip Thanh
  • 2026-06-18: advisory: Patchstack advisory published
  • 2026-06-25: disclosed: NVD publication date
  • 2026-06-25: patched: Version 1.3.9 released to address the vulnerability

References