CVE · Medium

CVE-2025-14371 — Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.42.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14371 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.42.0 Missing Authorization Medium 4.3 < 3.42.0 3.42.0 2026-01-05

CVE-2025-14371

A WordPress plugin called Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI has a security flaw that allows certain users to modify data without permission. This issue arises from the lack of proper access control checks in the taxopress_ai_add_post_term function, which affects all versions up to 3.41.0. As a result, authenticated users with Contributor-level privileges or higher can add or delete taxonomy terms on any post, regardless of ownership.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.