VYPR

Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI

by WordPress

CVEs (5)

  • CVE-2025-13922MedDec 6, 2025
    risk 0.42cvss 6.5epss 0.00

    The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'existing_terms_orderby' parameter in the AI preview AJAX endpoint in all versions up to, and including, 3.40.1. This is due to…

  • CVE-2025-13359MedDec 3, 2025
    risk 0.35cvss 6.5epss 0.00

    The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the "getTermsForAjax" function in all versions up to, and including, 3.40.1. This is due to insufficient escaping on the user supplied…

  • CVE-2025-14371MedJan 6, 2026
    risk 0.28cvss 4.3epss 0.00

    The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the taxopress_ai_add_post_term function in all versions up to, and including, 3.41.0. This makes it…

  • CVE-2025-11972MedNov 8, 2025
    risk 0.25cvss 4.9epss 0.00

    The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection via the 'post_types' parameter in all versions up to, and including, 3.40.0 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2025-13354MedDec 3, 2025
    risk 0.21cvss 4.3epss 0.00

    The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the…