Vulnerability Description
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the "taxopress_merge_terms_batch" function. This makes it possible for authenticated attackers, with subscriber level access and above, to merge or delete arbitrary taxonomy terms.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Taxopress | Taxopress | < 3.41.0 |
Related Weaknesses (CWE)
References
- https://github.com/TaxoPress/TaxoPress/commit/5eb2cee861ebd109152eea968aca0259c0Patch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/05c1ee52-02c9-440b-926Third Party Advisory
FAQ
What is CVE-2025-13354?
CVE-2025-13354 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is due to the plugin n...
How severe is CVE-2025-13354?
CVE-2025-13354 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-13354?
Check the references section above for vendor advisories and patch information. Affected products include: Taxopress Taxopress.