TaxoPress Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI
cpe:2.3:a:taxopress:taxopress:*:*:*:*:wordpress:*:*
- <= 3.40.1
A vulnerability exists in the Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress, in all versions up to and including 3.40.1. The issue stems from the plugin's failure to properly verify user authorization in the 'taxopress_merge_terms_batch' function. This flaw allows authenticated attackers with subscriber-level access or higher to merge or delete arbitrary taxonomy terms.
Exploitation of this vulnerability allows for unauthorized manipulation of taxonomy terms, including merging or deleting terms at will.
Users are advised to update the plugin to version 3.41.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.