CVE · Medium

CVE-2021-24444 — Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.0.7.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24444 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.0.7.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.0.7.2 3.0.7.2 2021-06-30

CVE-2021-24444

The TaxoPress plugin versions prior to 3.0.7.2 contain a stored cross-site scripting vulnerability in the taxonomy description field. Administrators and other high-privilege users can inject malicious JavaScript code into taxonomy descriptions, bypassing restrictions on the unfiltered_html capability due to improper input sanitization. This vulnerability allows attackers with elevated permissions to execute arbitrary scripts that persist in the database and affect other users viewing the affected taxonomies.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.