Description
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the "taxopress_merge_terms_batch" function. This makes it possible for authenticated attackers, with subscriber level access and above, to merge or delete arbitrary taxonomy terms.
Problem types
Product status
* (semver)
Timeline
| 2025-11-08: | Discovered |
| 2025-11-18: | Vendor Notified |
| 2025-12-03: | Disclosed |
Credits
M Indra Purnama
References
www.wordfence.com/...-02c9-440b-9269-14ea8b73be45?source=cve
github.com/...ommit/5eb2cee861ebd109152eea968aca0259c078c8b0