PLUGIN SECURITY
Is Simple Tags safe?
Tags, Categories and WordPress terms are easy with TaxoPress. Add a Tag or Category to Pages, manage your WooCommerce Categories and Tags and more.
What this plugin does
- Slug:
simple-tags - Author: Steve Burge
- 40000+ active installs
- 92/100 rating (194 reviews on wordpress.org)
- 6046134 all-time downloads
- On WordPress.org since 2007-10-10
categoriescategorytagtag cloudtaxonomy
Maintenance status
- Latest known version: 3.51.0
- Last updated: 2026-08-20 1:51pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
15 known CVEs on file for Simple Tags.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-74012 | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.52.0 | Deserialization of Untrusted Data | High 8.8 | < 3.52.0 | 3.52.0 | 2026-08-18 | ⚠ update needed |
| CVE-2026-15231 | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.51.0 | Authorization Bypass Through User-Controlled Key | Unknown | < 3.51.0 | 3.51.0 | 2026-08-03 | ✓ fixed in latest |
| CVE-2026-42646 | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.45.0 | — | High 7.6 | < 3.45.0 | 3.45.0 | 2026-03-22 | ✓ fixed in latest |
| CVE-2025-14371 | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.42.0 | Missing Authorization | Medium 4.3 | < 3.42.0 | 3.42.0 | 2026-01-05 | ✓ fixed in latest |
| CVE-2025-13922 | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.41.0 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 3.41.0 | 3.41.0 | 2025-12-05 | ✓ fixed in latest |
| CVE-2025-13359 | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.41.0 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 6.5 | < 3.41.0 | 3.41.0 | 2025-12-03 | ✓ fixed in latest |
| CVE-2025-13354 | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.41.0 | Missing Authorization | Medium 4.3 | < 3.41.0 | 3.41.0 | 2025-12-03 | ✓ fixed in latest |
| CVE-2025-11972 | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.40.1 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Medium 4.9 | < 3.40.1 | 3.40.1 | 2025-11-07 | ✓ fixed in latest |
+ 12 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-55710 | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.37.3 | Insertion of Sensitive Information Into Sent Data | Medium 4.3 | < 3.37.3 | 3.37.3 | 2025-08-14 | ✓ fixed in latest |
| CVE-2024-2830 | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.20.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 3.20.0 | 3.20.0 | 2024-04-03 | ✓ fixed in latest |
| CVE-2023-2168, CVE-2023-2169, CVE-2023-2170 | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 3.6.5 | 3.6.5 | 2023-04-18 | ✓ fixed in latest |
| CVE-2023-2169 | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 3.6.5 | 3.6.5 | 2023-04-18 | ✓ fixed in latest |
| CVE-2023-2170 | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 3.6.5 | 3.6.5 | 2023-04-18 | ✓ fixed in latest |
| — | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.4.5 | — | Unknown | < 3.4.5 | 3.4.5 | 2023-02-07 | ✓ fixed in latest |
| — | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.4.5 | — | Unknown | < 3.4.5 | 3.4.5 | 2022-02-07 | ✓ fixed in latest |
| CVE-2021-24444 | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.0.7.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 3.0.7.2 | 3.0.7.2 | 2021-06-30 | ✓ fixed in latest |
| — | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.30.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Low 3.5 | < 3.30.0 | 3.30.0 | 0000-00-00 | ✓ fixed in latest |
| — | Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.4.5 | — | Unknown | < 3.4.5 | 3.4.5 | — | ✓ fixed in latest |
| — | TaxoPress < 3.4.5 - Reflected Cross-Site Scripting | — | Unknown | < 3.4.5 | 3.4.5 | — | ✓ fixed in latest |
| CVE-2025-0627 | AI Autotagger < 3.30.0 - Admin+ Stored XSS | — | Unknown | < 3.30.0 | 3.30.0 | — | ✓ fixed in latest |
How to fix it
Keep Simple Tags updated — 3.51.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- List category posts — 80000+ active installs — 94/100 (254) — max PHP 8.4
- Media Library Assistant — 70000+ active installs — 96/100 (201) — max PHP 8.4
- Pages with category and tag — 50000+ active installs — 96/100 (28) — max PHP 8.4
- Search & Filter — 50000+ active installs — 90/100 (175) — max PHP 8.4
- Category Posts Block — 40000+ active installs — 90/100 (79) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.