The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
We have discovered 2,082 live websites that are affected by CVE-2025-0627.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 2,082 live websites (16% of Simple Tags install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 77 versions ( 81% of all versions) |
| 487 websites | |
| 268 websites | |
| 254 websites | |
| 200 websites | |
| 193 websites | |
| 128 websites | |
| 46 websites | |
| 41 websites | |
| 38 websites | |
| 37 websites |
| .com | 849 websites |
| .ru | 173 websites |
| .net | 146 websites |
| .it | 136 websites |
| .de | 101 websites |
| .org | 98 websites |
| .jp | 62 websites |
| .fr | 56 websites |
| .info | 43 websites |
| .pl | 30 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.org | *,*** | ||
| *******.com | *,*** | ||
| ******.com | *,*** | ||
| ****************.com | *,*** | ||
| ****.org | **,*** | ||
| **********.org | **,*** | ||
| **************.com | **,*** | ||
| *********************.com | **,*** | ||
| ***********.com | **,*** | ||
| *************.com | **,*** |
FAQ