plugin

Simple Tags Vulnerabilities

31 known security issues reported for the Simple Tags WordPress plugin. Most recent disclosed Aug 19, 2026.

16 medium

Running Simple Tags on your site? Check whether your installed version is affected.

Scan your site free

Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms <= 3.51.0 - Authenticated (Editor+) PHP Object Injection

medium

The Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.51.0. This is due to deserialization of untrusted input. This makes it possible for authenticated attackers, with editor-level access and above,...

CVSS:
6.6
Affected:
up to 3.51.0
Fixed in:
3.52.0
Disclosed:
Aug 19, 2026

CVE-2026-74012 on NVD →

TaxoPress <= 3.50.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Private Post Disclosure

medium

The TaxoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.50.0. This is due to missing authorization check on a user-supplied post ID passed to get_post() in the AI preview AJAX handler, allowing any authenticated user to retrieve post data regardless of po...

CVSS:
4.3
Affected:
up to 3.50.0
Fixed in:
3.51.0
Disclosed:
Jul 24, 2026

CVE-2026-15231 on NVD →

TaxoPress <= 3.44.0 - Authenticated (Editor+) SQL Injection

medium

The TaxoPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.44.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above, to...

CVSS:
4.9
Affected:
up to 3.44.0
Fixed in:
3.45.0
Disclosed:
Mar 22, 2026

CVE-2026-42646 on NVD →

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.42.0

unknown

[en] The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the taxopress_ai_add_post_term function in all versions up to, and including, 3.41.0. This makes it possible for authenticated attackers,...

Affected:
up to 3.42.0
Fixed in:
3.42.0
Disclosed:
Jan 6, 2026

CVE-2025-14371 on NVD →

TaxoPress <= 3.41.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Tag Modification

medium

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the taxopress_ai_add_post_term function in all versions up to, and including, 3.41.0. This makes it possible for authenticated attackers, with...

CVSS:
4.3
Affected:
up to 3.41.0
Fixed in:
3.42.0
Disclosed:
Jan 5, 2026

CVE-2025-14371 on NVD →

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.41.0

unknown

[en] The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'existing_terms_orderby' parameter in the AI preview AJAX endpoint in all versions up to, and including, 3.40.1. This is due to insufficient escaping on user-supplied par...

Affected:
up to 3.41.0
Fixed in:
3.41.0
Disclosed:
Dec 6, 2025

CVE-2025-13922 on NVD →

Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI <= 3.40.1 - Authenticated (Contributor+) SQL Injection via ORDER BY Clause

medium

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'existing_terms_orderby' parameter in the AI preview AJAX endpoint in all versions up to, and including, 3.40.1. This is due to insufficient escaping on user-supplied paramete...

CVSS:
6.5
Affected:
up to 3.40.1
Fixed in:
3.41.0
Disclosed:
Dec 5, 2025

CVE-2025-13922 on NVD →

Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI <= 3.40.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Taxonomy Term Manipulation

medium

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the "taxopress_merge_terms_batch" function. This...

CVSS:
4.3
Affected:
up to 3.40.1
Fixed in:
3.41.0
Disclosed:
Dec 3, 2025

CVE-2025-13354 on NVD →

Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI <= 3.40.1 - Authenticated (Contributor+) SQL Injection

medium

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the "getTermsForAjax" function in all versions up to, and including, 3.40.1. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on...

CVSS:
6.5
Affected:
up to 3.40.1
Fixed in:
3.41.0
Disclosed:
Dec 3, 2025

CVE-2025-13359 on NVD →

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.41.0

unknown

[en] The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the "getTermsForAjax" function in all versions up to, and including, 3.40.1. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparatio...

Affected:
up to 3.41.0
Fixed in:
3.41.0
Disclosed:
Dec 3, 2025

CVE-2025-13359 on NVD →

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.41.0

unknown

[en] The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the "taxopress_merge_terms_batch" function....

Affected:
up to 3.41.0
Fixed in:
3.41.0
Disclosed:
Dec 3, 2025

CVE-2025-13354 on NVD →

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.40.1

unknown

[en] The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection via the 'post_types' parameter in all versions up to, and including, 3.40.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL quer...

Affected:
up to 3.40.1
Fixed in:
3.40.1
Disclosed:
Nov 8, 2025

CVE-2025-11972 on NVD →

Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI <= 3.40.0 - Authenticated (Editor+) SQL Injection

medium

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection via the 'post_types' parameter in all versions up to, and including, 3.40.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. T...

CVSS:
4.9
Affected:
up to 3.40.0
Fixed in:
3.40.1
Disclosed:
Nov 7, 2025

CVE-2025-11972 on NVD →

Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI <= 3.37.2 - Authenticated (Subscriber+) Information Exposure

medium

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.37.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration da...

CVSS:
4.3
Affected:
up to 3.37.2
Fixed in:
3.37.3
Disclosed:
Aug 14, 2025

CVE-2025-55710 on NVD →

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.37.3

unknown

[en] Insertion of Sensitive Information Into Sent Data vulnerability in Steve Burge TaxoPress allows Retrieve Embedded Sensitive Data. This issue affects TaxoPress: from n/a through 3.37.2.

Affected:
up to 3.37.3
Fixed in:
3.37.3
Disclosed:
Aug 14, 2025

CVE-2025-55710 on NVD →

WordPress Tag, Category, and Taxonomy Manager – AI Autotagger <= 3.32.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WordPress Tag, Category, and Taxonomy Manager – AI Autotagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.32.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with adminis...

CVSS:
4.4
Affected:
up to 3.32.0
Fixed in:
3.33.0
Disclosed:
Apr 7, 2025

CVE-2025-0627 on NVD →

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.20.0

unknown

[en] The WordPress Tag and Category Manager – AI Autotagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'st_tag_cloud' shortcode in all versions up to, and including, 3.13.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possi...

Affected:
up to 3.20.0
Fixed in:
3.20.0
Disclosed:
Apr 4, 2024

CVE-2024-2830 on NVD →

WordPress Tag and Category Manager – AI Autotagger <= 3.13.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The WordPress Tag and Category Manager – AI Autotagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'st_tag_cloud' shortcode in all versions up to, and including, 3.13.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f...

CVSS:
6.4
Affected:
up to 3.12.0
Fixed in:
3.20.0
Disclosed:
Apr 3, 2024

CVE-2024-2830 on NVD →

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.6.5

unknown

[en] The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web...

Affected:
up to 3.6.5
Fixed in:
3.6.5
Disclosed:
Apr 19, 2023

CVE-2023-2170 on NVD →

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.6.5

unknown

[en] The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web...

Affected:
up to 3.6.5
Fixed in:
3.6.5
Disclosed:
Apr 19, 2023

CVE-2023-2169 on NVD →

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.6.5

unknown

[en] The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Suggest Terms Title field in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web s...

Affected:
up to 3.6.5
Fixed in:
3.6.5
Disclosed:
Apr 19, 2023

CVE-2023-2168 on NVD →

TaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scri...

CVSS:
5.5
Affected:
up to 3.6.4
Fixed in:
3.6.5
Disclosed:
Apr 18, 2023

CVE-2023-2170 on NVD →

TaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web scri...

CVSS:
5.5
Affected:
up to 3.6.4
Fixed in:
3.6.5
Disclosed:
Apr 18, 2023

CVE-2023-2169 on NVD →

TaxoPress <= 3.6.4 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Suggest Terms Title field in versions up to, and including, 3.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Editor+ permissions to inject arbitrary web script...

CVSS:
5.5
Affected:
up to 3.6.4
Fixed in:
3.6.5
Disclosed:
Apr 18, 2023

CVE-2023-2168 on NVD →

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.4.5

unknown

Update the WordPress TaxoPress plugin to the latest available version (at least 3.4.5). WPScanTeam discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress TaxoPress Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloa...

Affected:
up to 3.4.5
Fixed in:
3.4.5
Disclosed:
Feb 7, 2023

TaxoPress <= 3.4.4 - Reflected Cross-Site Scripting

medium

The TaxoPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.4.4 due to missing input and output sanitization of some user generated URLs.

CVSS:
6.1
Affected:
up to 3.4.4
Fixed in:
3.4.5
Disclosed:
Feb 7, 2022

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.4.5

unknown

The TaxoPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.4.4 due to missing input and output sanitization of some user generated URLs.

Affected:
up to 3.4.5
Fixed in:
3.4.5
Disclosed:
Feb 7, 2022

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.0.7.2

unknown

[en] The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scri...

Affected:
up to 3.0.7.2
Fixed in:
3.0.7.2
Disclosed:
Aug 2, 2021

CVE-2021-24444 on NVD →

TaxoPress <= 3.0.7.1 - Stored Cross-Site Scripting

medium

The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to set JavaScript payload in them even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting...

CVSS:
5.5
Affected:
up to 3.0.7.1
Fixed in:
3.0.7.2
Disclosed:
Jun 30, 2021

CVE-2021-24444 on NVD →

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.4.5

unknown

The plugin does not escape some generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 3.4.5
Fixed in:
3.4.5

Tag, Category, and Taxonomy Manager &#8211; AI Autotagger with OpenAI [simple-tags] < 3.30.0

unknown
Affected:
up to 3.30.0
Fixed in:
3.30.0

CVE-2025-0627 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database