PLUGIN SECURITY

Is Simple Tags safe?

Tags, Categories and WordPress terms are easy with TaxoPress. Add a Tag or Category to Pages, manage your WooCommerce Categories and Tags and more.

What this plugin does

  • Slug: simple-tags
  • Author: Steve Burge
  • 40000+ active installs
  • 92/100 rating (194 reviews on wordpress.org)
  • 6046134 all-time downloads
  • On WordPress.org since 2007-10-10

categoriescategorytagtag cloudtaxonomy

Maintenance status

  • Latest known version: 3.51.0
  • Last updated: 2026-08-20 1:51pm GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

15 known CVEs on file for Simple Tags.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-74012 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.52.0 Deserialization of Untrusted Data High 8.8 < 3.52.0 3.52.0 2026-08-18 ⚠ update needed
CVE-2026-15231 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.51.0 Authorization Bypass Through User-Controlled Key Unknown < 3.51.0 3.51.0 2026-08-03 ✓ fixed in latest
CVE-2026-42646 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.45.0 High 7.6 < 3.45.0 3.45.0 2026-03-22 ✓ fixed in latest
CVE-2025-14371 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.42.0 Missing Authorization Medium 4.3 < 3.42.0 3.42.0 2026-01-05 ✓ fixed in latest
CVE-2025-13922 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.41.0 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 6.5 < 3.41.0 3.41.0 2025-12-05 ✓ fixed in latest
CVE-2025-13359 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.41.0 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 6.5 < 3.41.0 3.41.0 2025-12-03 ✓ fixed in latest
CVE-2025-13354 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.41.0 Missing Authorization Medium 4.3 < 3.41.0 3.41.0 2025-12-03 ✓ fixed in latest
CVE-2025-11972 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.40.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 4.9 < 3.40.1 3.40.1 2025-11-07 ✓ fixed in latest
+ 12 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-55710 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.37.3 Insertion of Sensitive Information Into Sent Data Medium 4.3 < 3.37.3 3.37.3 2025-08-14 ✓ fixed in latest
CVE-2024-2830 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.20.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 3.20.0 3.20.0 2024-04-03 ✓ fixed in latest
CVE-2023-2168, CVE-2023-2169, CVE-2023-2170 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.6.5 3.6.5 2023-04-18 ✓ fixed in latest
CVE-2023-2169 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.6.5 3.6.5 2023-04-18 ✓ fixed in latest
CVE-2023-2170 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.6.5 3.6.5 2023-04-18 ✓ fixed in latest
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.4.5 Unknown < 3.4.5 3.4.5 2023-02-07 ✓ fixed in latest
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.4.5 Unknown < 3.4.5 3.4.5 2022-02-07 ✓ fixed in latest
CVE-2021-24444 Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.0.7.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.0.7.2 3.0.7.2 2021-06-30 ✓ fixed in latest
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.30.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Low 3.5 < 3.30.0 3.30.0 0000-00-00 ✓ fixed in latest
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.4.5 Unknown < 3.4.5 3.4.5 ✓ fixed in latest
TaxoPress < 3.4.5 - Reflected Cross-Site Scripting Unknown < 3.4.5 3.4.5 ✓ fixed in latest
CVE-2025-0627 AI Autotagger < 3.30.0 - Admin+ Stored XSS Unknown < 3.30.0 3.30.0 ✓ fixed in latest

How to fix it

Keep Simple Tags updated — 3.51.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.