{"error":0,"message":null,"data":{"name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms","plugin":"simple-tags","link":"https:\/\/wordpress.org\/plugins\/simple-tags\/","latest":"1788421920","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"d573ff4be3226b4cc46ad314cdaddf6ef2db0e6a313124e1879ffaa9fa876225","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.0.7.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.7.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24444","name":"CVE-2021-24444","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24444","description":"[en] The TaxoPress \u2013 Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue.","date":"2021-08-02"},{"id":"a9d8bdb3d62edda326d04cd4269308962bfc47dc","name":"WordPress TaxoPress plugin <= 3.0.7.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/simple-tags\/vulnerability\/wordpress-taxopress-plugin-3-0-7-1-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Akash Rajendra Patil in WordPress TaxoPress plugin (versions <= 3.0.7.1).","date":"2021-06-30"},{"id":"19a5174bf50208c2d93daed971955a593a1037e8","name":"TaxoPress <= 3.0.7.1 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/taxopress-3071-stored-cross-site-scripting","description":"The TaxoPress \u2013 Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue.","date":"2021-06-30"},{"id":"a31321fe-adc6-4480-a220-35aedca52b8b","name":"TaxoPress &lt; 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/a31321fe-adc6-4480-a220-35aedca52b8b","description":"The plugin does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"9fd12038f7671681b7d5d4f68dbec879b14d275565ac162b7a39a35cc51bbac2","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"725f4d7ae3507b77a248c59e57beafdb1cafb51e","name":"TaxoPress <= 3.4.4 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/taxopress-344-reflected-cross-site-scripting","description":"The TaxoPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.4.4 due to missing input and output sanitization of some user generated URLs.","date":"2022-02-07"}],"impact":[]},{"uuid":"80dfca9e1cfd0b19ae860fa369f8b81aa67a08a78b0d0daf5fc7a6bd7429dddd","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-2168","name":"CVE-2023-2168","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2168","description":"[en] The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Suggest Terms Title field in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-04-19"},{"id":"b710f8f605a5997b7e1a1daaaf713f4d312066e6","name":"TaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/taxopress-364-authenticated-editor-stored-cross-site-scripting","description":"The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Suggest Terms Title field in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-04-18"},{"id":"6f03a5f6132c746850141812da37b320a5301f2d","name":"WordPress  TaxoPress Plugin  <= 3.6.4 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/simple-tags\/vulnerability\/wordpress-taxopress-plugin-3-6-4-authenticated-editor-stored-cross-site-scripting-vulnerability","description":"Update the WordPress TaxoPress plugin to the latest available version (at least 3.6.5).\nIvan Kuzymchak discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress TaxoPress Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.6.5.","date":"2023-04-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9c2c745b9cadfc8c87cccfe784d726800601d6354b942cb8a99e0213c73a1c16","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-2169","name":"CVE-2023-2169","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2169","description":"[en] The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-04-19"},{"id":"d56225f68c1333028b560e387a9042a0d66d0139","name":"TaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/taxopress-364-authenticated-editor-stored-cross-site-scripting-1","description":"The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-04-18"},{"id":"51924ab51547dc9b3522a5087aed2ca9b0a70c31","name":"WordPress  TaxoPress Plugin  < 3.6.5 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/simple-tags\/vulnerability\/wordpress-taxopress-plugin-3-6-5-auth-stored-cross-site-scripting-xss-vulnerability","description":"Update the WordPress TaxoPress plugin to the latest available version (at least 3.6.5).\nIvan Kuzymchak discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress TaxoPress Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.6.5.","date":"2023-04-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"183f3777c85ddd38c5fd3509b8db80718d90eb958f4acd1476dc4a303c58ab2e","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-2170","name":"CVE-2023-2170","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2170","description":"[en] The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-04-19"},{"id":"17be3c63374c7fcd9adb5044f658ae84ec59c17a","name":"TaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/taxopress-364-authenticated-editor-stored-cross-site-scripting-2","description":"The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-04-18"},{"id":"e0c776eb6f947b5fd59f14434e7af8cbf19e845a","name":"WordPress  TaxoPress Plugin  < 3.6.5 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/simple-tags\/vulnerability\/wordpress-taxopress-plugin-3-6-5-auth-stored-cross-site-scripting-xss-vulnerability-2","description":"Update the WordPress TaxoPress plugin to the latest available version (at least 3.6.5).\nIvan Kuzymchak discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress TaxoPress Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.6.5.","date":"2023-04-19"},{"id":"bcba8a87-4c9e-4b0e-a47e-f89da994d1c3","name":"TaxoPress &lt; 3.6.5 - Editor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/bcba8a87-4c9e-4b0e-a47e-f89da994d1c3","description":"The plugin does not sanitise and escape some parameters, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c5e760db6816f146e62fca46ef36aa42000b1539f58f8e79f517cf47b7aca4e6","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b906aa3b9e061a276e110ef20b96ef5743bb2f5d","name":"WordPress  TaxoPress Plugin  <= 3.4.4 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/simple-tags\/vulnerability\/wordpress-taxopress-plugin-3-4-4-reflected-cross-site-scripting-xss-vulnerability","description":"Update the WordPress TaxoPress plugin to the latest available version (at least 3.4.5).\nWPScanTeam discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress TaxoPress Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.4.5.","date":"2023-02-07"}],"impact":[]},{"uuid":"f88e5d3b217ea2f8be484863b9c7634de64b732dfb75b34351a18daaf4851d49","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b5509e79-1f17-48be-afcb-26329112dd9f","name":"TaxoPress &lt; 3.4.5 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/b5509e79-1f17-48be-afcb-26329112dd9f","description":"The plugin does not escape some generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting","date":null}],"impact":[]},{"uuid":"bae7e2b92fd61017629a77f44d8af3a2f636ae73c29519b6378df00050638569","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.20.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.20.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2830","name":"CVE-2024-2830","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2830","description":"[en] The WordPress Tag and Category Manager \u2013 AI Autotagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'st_tag_cloud' shortcode in all versions up to, and including, 3.13.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-04"},{"id":"4b9704eb6b786f3b8e175a7c8491e80ca48043af","name":"WordPress Tag and Category Manager \u2013 AI Autotagger <= 3.13.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/wordpress-tag-and-category-manager-ai-autotagger-3130-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The WordPress Tag and Category Manager \u2013 AI Autotagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'st_tag_cloud' shortcode in all versions up to, and including, 3.13.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-03"},{"id":"59f10e81cae8aff641dc96793e265747945fa145","name":"WordPress  TaxoPress Plugin    <= 3.12.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/simple-tags\/vulnerability\/wordpress-taxopress-plugin-3-13-0-authenticated-contributor-stored-cross-site-scripting-via-shortcode-vulnerability","description":"Update the WordPress TaxoPress plugin to the latest available version (at least 3.20.0).\nstealthcopter discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress TaxoPress Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.20.0.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"fb667a6e563ed2704ed9fd4242be06726e264cd5a113cd980e3626eccdb1b175","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.30.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.30.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-0627","name":"AI Autotagger < 3.30.0 - Admin+ Stored XSS","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-0627","description":"The WordPress Tag, Category, and Taxonomy Manager  WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"0000-00-00"},{"id":"77667c670ea73c1d9ce0b5ab21af7483c501e59b","name":"WordPress TaxoPress Plugin < 3.30.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/simple-tags\/vulnerability\/wordpress-ai-autotagger-plugin-3-30-0-admin-stored-xss-vulnerability","description":"<p>WordPress TaxoPress Plugin < 3.30.0 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: TaxoPress<\/p><p>Fixed in version 3.30.0 <\/p><p>Affected Version < 3.30.0<\/p><p>CVE: CVE-2025-0627<\/p>","date":"2025-04-28"},{"id":"EUVD-2025-12550","name":"EUVD-2025-12550","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-12550","description":"The WordPress Tag, Category, and Taxonomy Manager  WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"2025-04-28"},{"id":"0d410b6bf8218e7c9e16558c2c164539544a5e2b","name":"WordPress Tag, Category, and Taxonomy Manager \u2013 AI Autotagger <= 3.32.0 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/wordpress-tag-category-and-taxonomy-manager-ai-autotagger-3320-authenticated-admin-stored-cross-site-scripting","description":"The WordPress Tag, Category, and Taxonomy Manager \u2013 AI Autotagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.32.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2025-04-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"u","c":"l","i":"l","a":"n","score":"3.5","severity":"l","exploitable":"0.9","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:U\/C:L\/I:L\/A:N","score":"3.5","severity":"low","av":"network","ac":"low","pr":"high","ui":"required","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"0.9","impact":"2.5"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9768780a170cb6508de6ffbc4f58942dd8a1284ba1fbea0c5ef48e8af49cb5f8","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.37.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.37.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-55710","name":"CVE-2025-55710","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-55710","description":"[en] Insertion of Sensitive Information Into Sent Data vulnerability in Steve Burge TaxoPress allows Retrieve Embedded Sensitive Data. This issue affects TaxoPress: from n\/a through 3.37.2.","date":"2025-08-14"},{"id":"bbd3be31de9c44c8d02df8060864a2e302f493a2","name":"Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI <= 3.37.2 - Authenticated (Subscriber+) Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/tag-category-and-taxonomy-manager-ai-autotagger-with-openai-3372-authenticated-subscriber-information-exposure","description":"The Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.37.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.","date":"2025-08-14"},{"id":"EUVD-2025-24923","name":"EUVD-2025-24923","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-24923","description":"Insertion of Sensitive Information Into Sent Data vulnerability in Steve Burge TaxoPress allows Retrieve Embedded Sensitive Data. This issue affects TaxoPress: from n\/a through 3.37.2.","date":"2025-08-14"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-201","name":"Insertion of Sensitive Information Into Sent Data","description":"The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":null,"impact":null}}},{"uuid":"4507d282e9ecee77e71f73b62edc8ee9278f70d0116aa95e3e6342df2cb2ce1b","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.40.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.40.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-11972","name":"CVE-2025-11972","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-11972","description":"[en] The Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection via the 'post_types' parameter in all versions up to, and including, 3.40.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-11-08"},{"id":"63e8da1a8745c1cceb82b5bddd42e5c73b6ac810","name":"Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI <= 3.40.0 - Authenticated (Editor+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/tag-category-and-taxonomy-manager-ai-autotagger-with-openai-3400-authenticated-editor-sql-injection","description":"The Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection via the 'post_types' parameter in all versions up to, and including, 3.40.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-11-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"4.9","severity":"m","exploitable":"1.2","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"4.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"1.2","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3afeb961206d5d040e01560c2a5762ea99af2285fd39e44b908b0e18bc1550c3","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.41.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.41.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-13359","name":"CVE-2025-13359","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-13359","description":"[en] The Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the \"getTermsForAjax\"  function in all versions up to, and including, 3.40.1. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database granted they have metabox access for the taxonomy (enabled by default for contributors).","date":"2025-12-03"},{"id":"d6dd97210da35aea122293059fed05ca4e9faabe","name":"Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI <= 3.40.1 - Authenticated (Contributor+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/tag-category-and-taxonomy-manager-ai-autotagger-with-openai-3401-authenticated-contributor-sql-injection","description":"The Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the \"getTermsForAjax\"  function in all versions up to, and including, 3.40.1. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database granted they have metabox access for the taxonomy (enabled by default for contributors).","date":"2025-12-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"38734c83857b5bc8066bd2e6642513fe45eec8f9877c1a995f4c35dd9ea6f7cf","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.41.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.41.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-13354","name":"CVE-2025-13354","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-13354","description":"[en] The Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the \"taxopress_merge_terms_batch\" function. This makes it possible for authenticated attackers, with subscriber level access and above, to merge or delete arbitrary taxonomy terms.","date":"2025-12-03"},{"id":"320239e1ea5a126cdda268a62369aea2318f625a","name":"Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI <= 3.40.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Taxonomy Term Manipulation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/tag-category-and-taxonomy-manager-ai-autotagger-with-openai-3401-missing-authorization-to-authenticated-subscriber-arbitrary-taxonomy-term-manipulation","description":"The Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the \"taxopress_merge_terms_batch\" function. This makes it possible for authenticated attackers, with subscriber level access and above, to merge or delete arbitrary taxonomy terms.","date":"2025-12-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b368df2b7970439ecf6a248b2a8fa2fa7897e664a956fe7066c31bce3eee1060","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.41.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.41.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-13922","name":"CVE-2025-13922","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-13922","description":"[en] The Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'existing_terms_orderby' parameter in the AI preview AJAX endpoint in all versions up to, and including, 3.40.1. This is due to insufficient escaping on user-supplied parameters and lack of SQL query parameterization. This makes it possible for authenticated attackers, with Contributor-level access and above who have AI metabox permissions, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database, cause performance degradation, or enable data inference through time-based techniques.","date":"2025-12-06"},{"id":"912a53ff7f86985e56b18fc9e77f16721b4297cb","name":"Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI <= 3.40.1 - Authenticated (Contributor+) SQL Injection via ORDER BY Clause","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/tag-category-and-taxonomy-manager-ai-autotagger-with-openai-3401-authenticated-contributor-sql-injection-via-order-by-clause","description":"The Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'existing_terms_orderby' parameter in the AI preview AJAX endpoint in all versions up to, and including, 3.40.1. This is due to insufficient escaping on user-supplied parameters and lack of SQL query parameterization. This makes it possible for authenticated attackers, with Contributor-level access and above who have AI metabox permissions, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database, cause performance degradation, or enable data inference through time-based techniques.","date":"2025-12-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"2641de2cbda8619c778b396163be0f22036d698961d697afe4fe0ca364218b22","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.42.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.42.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-14371","name":"CVE-2025-14371","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-14371","description":"[en] The Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the taxopress_ai_add_post_term function in all versions up to, and including, 3.41.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to add or remove taxonomy terms (tags, categories) on any post, including ones they do not own.","date":"2026-01-06"},{"id":"8c4bd3a5e4d0df9c14b2d35eb1ea66cc0f837926","name":"TaxoPress <= 3.41.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Tag Modification","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/taxopress-3410-missing-authorization-to-authenticated-contributor-arbitrary-post-tag-modification","description":"The Tag, Category, and Taxonomy Manager \u2013 AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the taxopress_ai_add_post_term function in all versions up to, and including, 3.41.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to add or remove taxonomy terms (tags, categories) on any post, including ones they do not own.","date":"2026-01-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"568a423b8f2190a11c3c95c94ed18bb27084e0fc921d5d10023e5af9a6fec8dc","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.45.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.45.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-42646","name":"CVE-2026-42646","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-42646","description":"[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPress simple-tags allows Blind SQL Injection.This issue affects TaxoPress: from n\/a through <= 3.44.0.","date":"2026-04-29"},{"id":"1886fafa59ef522a0e14d765d772fded27f01139","name":"TaxoPress <= 3.44.0 - Authenticated (Editor+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/taxopress-3440-authenticated-editor-sql-injection","description":"The TaxoPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.44.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-03-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:N\/A:L","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"h","i":"n","a":"l","score":"7.6","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:N\/A:L","score":"7.6","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"changed","c":"high","i":"none","a":"low","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"99163c1c2f9a9aa28de33c26625a965627e215d7a55b589f0e05aedbd0191da2","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.51.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.51.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15231","name":"CVE-2026-15231","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15231","description":"[en] The Tag, Category, and Taxonomy Manager  WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.","date":"2026-08-03"}],"impact":{"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3db9f2f0b9d46b0f4b82bdc226a84d15266d696dffc76bd92346cafc932ae5d5","name":"Tag, Category, and Taxonomy Manager &#8211; Autotagger Automatically Add Terms [simple-tags] < 3.52.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.52.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-74012","name":"CVE-2026-74012","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-74012","description":"[en] Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection.\n\nThis issue affects TaxoPress: from n\/a through 3.51.0.","date":"2026-08-18"},{"id":"530e24a88ff41efd10874ac30a1cf9bead9ec3ff","name":"Tag, Category, and Taxonomy Manager \u2013 Autotagger Automatically Add Terms &lt;= 3.51.0 - Authenticated (Editor+) PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/simple-tags\/tag-category-and-taxonomy-manager-autotagger-automatically-add-terms-3510-authenticated-editor-php-object-injection","description":"The Tag, Category, and Taxonomy Manager \u2013 Autotagger Automatically Add Terms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.51.0. This is due to deserialization of untrusted input. This makes it possible for authenticated attackers, with editor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}}]},"updated":"1787638895"}