CVE

CVE-2026-15231 — Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.51.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15231 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.51.0 Authorization Bypass Through User-Controlled Key Unknown < 3.51.0 3.51.0 2026-08-03

CVE-2026-15231

A vulnerability exists in the Tag, Category, and Taxonomy Manager plugin for WordPress prior to version 3.51.0, where an unauthorized user can access sensitive information from non-public posts by exploiting a lack of permission checks during post processing. This issue specifically affects users with contributor-level privileges who are not owners of private or draft posts they can still access.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.