
MDTF – Meta Data and Taxonomies Filter Security & Risk Analysis
wordpress.org/plugins/wp-meta-data-filter-and-taxonomy-filterThe main idea of the plugin – make your WordPress site content is filterable and searchable by meta fields and taxonomies on the same time.
Is MDTF – Meta Data and Taxonomies Filter Safe to Use in 2026?
High Risk
Score 40/100MDTF – Meta Data and Taxonomies Filter carries significant security risk with 19 known CVEs, 1 still unpatched. Consider switching to a maintained alternative.
The "wp-meta-data-filter-and-taxonomy-filter" plugin v1.3.6 presents a mixed security posture with some concerning aspects despite a generally good handling of output escaping and prepared statements. The static analysis reveals a substantial attack surface, with 25 out of 47 entry points lacking proper authorization checks. This is a significant concern, as it could allow unauthenticated users to trigger potentially sensitive actions. While the taint analysis did not reveal any critical or high-severity vulnerabilities, the presence of 7 flows with unsanitized paths warrants attention, as these could be vectors for vulnerabilities if exploited in conjunction with other weaknesses. The plugin's vulnerability history is particularly alarming, with a total of 19 known CVEs, including 2 critical and 4 high-severity vulnerabilities. The fact that one critical vulnerability remains unpatched is a severe risk. Common vulnerability types like XSS, Code Injection, SQL Injection, Missing Authorization, and CSRF in its history suggest recurring insecure coding practices that attackers have successfully exploited in the past.
Overall, the plugin exhibits a concerning pattern of past exploitable vulnerabilities, and the current version still has a significant number of unprotected entry points. While the code shows strengths in output escaping and the use of prepared statements for most SQL queries, the high number of unprotected AJAX handlers and the presence of unpatched historical vulnerabilities significantly elevate the risk. Users should exercise extreme caution, prioritize patching any known vulnerabilities, and ideally seek an updated version of the plugin that addresses these security deficiencies.
Key Concerns
- Unpatched critical CVE
- High number of unprotected AJAX handlers
- Flows with unsanitized paths (7 total)
- Missing authorization checks on AJAX handlers (25)
- Vulnerability history indicates recurring insecure practices
- Multiple high severity historical CVEs
- Total of 19 known CVEs historically
MDTF – Meta Data and Taxonomies Filter Security Vulnerabilities
CVEs by Year
Severity Breakdown
19 total CVEs
MDTF <= 1.3.3.9 - Missing Authorization
MDTF <= 1.3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
MDTF <= 1.3.4 - Missing Authorization
MDTF <= 1.3.3.7 - Unauthenticated SQL Injection
MDTF – Meta Data and Taxonomies Filter <= 1.3.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
MDTF – Meta Data and Taxonomies Filter <= 1.3.3.5 - Authenticated (Contributor+) SQL Injection
WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3.4 - Unauthenticated Arbitrary Shortcode Execution
WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
MDTF – Meta Data and Taxonomies Filter <= 1.3.3.3 - Authenticated (Contributor+) SQL Injection
MDTF – Meta Data and Taxonomies Filter <= 1.3.3.3 - Unauthenticated Arbitrary Shortcode Execution
WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3.2 - Unauthenticated Arbitrary Shortcode Execution
WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3 - Missing Authorization
WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3.1 - Cross-Site Request Forgery
WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting
WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
MDTF – Meta Data and Taxonomies Filter <= 1.3.0.1 - Relected Cross-Site Scripting via 'tax_name'
MDTF – Meta Data and Taxonomies Filter <= 1.3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Meta Data Filter & Taxonomies Filter <= 1.2.7.2 - Cross-Site Request Forgery
MDTF – Meta Data and Taxonomies Filter Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
MDTF – Meta Data and Taxonomies Filter Attack Surface
AJAX Handlers 30
Shortcodes 17
WordPress Hooks 68
Scheduled Events 2
Maintenance & Trust
MDTF – Meta Data and Taxonomies Filter Maintenance & Trust
Maintenance Signals
Community Trust
MDTF – Meta Data and Taxonomies Filter Alternatives
annasta Filters for WooCommerce
annasta-woocommerce-product-filters
All-in-one products search and filtering solution for your WooCommerce shop with rich features and customization options.
WOOF by Category
woof-by-category
WooCommerce Product Filter (WOOF) extension to display a set of filters depending on the current product category page.
Active Products Tables for WooCommerce. Use constructor to create tables
profit-products-tables-for-woocommerce
WooCommerce Active Products Tables - is the WooCommerce Products Table plugin displaying shop products in table format
Live Search and Custom Fields LITE – Advanced Filter
live-search-custom-fields-lite
Advanced WordPress Filter Plugin that helps you to create stunning filters on your website. Search and Filter WordPress posts, custom posts, WooCommer …
Shop Products Filter
trusty-woo-products-filter
Filter all products of your woocommerce shop. Filter by categories,tags,attributes,taxonomies,price slider,on sale etc.
MDTF – Meta Data and Taxonomies Filter Developer Profile
12 plugins · 188K total installs
How We Detect MDTF – Meta Data and Taxonomies Filter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-meta-data-filter-and-taxonomy-filter/css/mdf_settings.css/wp-content/plugins/wp-meta-data-filter-and-taxonomy-filter/js/front.js/wp-content/plugins/wp-meta-data-filter-and-taxonomy-filter/js/mdf_settings.jsjs/front.jsjs/mdf_settings.jswp-meta-data-filter-and-taxonomy-filter/css/mdf_settings.css?ver=wp-meta-data-filter-and-taxonomy-filter/js/front.js?ver=wp-meta-data-filter-and-taxonomy-filter/js/mdf_settings.js?ver=HTML / DOM Fingerprints
data-mdf-slugdata-mdf-iddata-mdf-taxonomymdf_settings_data