CVE Database /
CVE-2025-13354
CVE · Medium
CVE-2025-13354 — Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.41.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-13354
|
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.41.0 |
Missing Authorization |
Medium
4.3
|
< 3.41.0
|
3.41.0 |
2025-12-03 |
—
|
CVE-2025-13354
A WordPress plugin for managing taxonomy terms and categories, which integrates with OpenAI's AI capabilities, has a security flaw that allows users with subscriber-level access or higher to bypass authorization checks. As a result, these users can merge or delete arbitrary taxonomy terms without proper permission, potentially leading to unintended changes in the site's taxonomy structure. This vulnerability affects all versions of the plugin up to and including 3.40.1.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings