The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the "taxopress_merge_terms_batch" function. This makes it possible for authenticated attackers, with subscriber level access and above, to merge or delete arbitrary taxonomy terms.
We have discovered 4,787 live websites that are affected by CVE-2025-13354.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 4,787 live websites (37% of Simple Tags install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 91 versions ( 96% of all versions) |
| 1,492 websites | |
| 481 websites | |
| 424 websites | |
| 348 websites | |
| 332 websites | |
| 322 websites | |
| 108 websites | |
| 101 websites | |
| 88 websites | |
| 85 websites |
| .com | 2,090 websites |
| .net | 285 websites |
| .ru | 252 websites |
| .it | 237 websites |
| .de | 231 websites |
| .org | 230 websites |
| .fr | 129 websites |
| .jp | 114 websites |
| .nl | 71 websites |
| .info | 70 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.org | *,*** | ||
| *******.com | *,*** | ||
| *********.com | *,*** | ||
| ******.com | *,*** | ||
| ****************.com | *,*** | ||
| ****.org | **,*** | ||
| *********.com | **,*** | ||
| ********.com | **,*** | ||
| **********.cz | **,*** | ||
| **********.org | **,*** |
FAQ