CVE · Medium

CVE-2025-13354 — Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.41.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13354 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.41.0 Missing Authorization Medium 4.3 < 3.41.0 3.41.0 2025-12-03

CVE-2025-13354

A WordPress plugin for managing taxonomy terms and categories, which integrates with OpenAI's AI capabilities, has a security flaw that allows users with subscriber-level access or higher to bypass authorization checks. As a result, these users can merge or delete arbitrary taxonomy terms without proper permission, potentially leading to unintended changes in the site's taxonomy structure. This vulnerability affects all versions of the plugin up to and including 3.40.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.