CVE-2025-14371

TaxoPress <= 3.41.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Tag Modification

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the taxopress_ai_add_post_term function in all versions up to, and including, 3.41.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to add or remove taxonomy terms (tags, categories) on any post, including ones they do not own.


We have discovered 5,216 live websites that are affected by CVE-2025-14371.

Run a Free Instant Scan




Affected Software

Product  Simple Tags
Category Wordpress Plugins
Vulnerable Domains5,216 live websites (41% of Simple Tags install base)
Vulnerable Versions
  • from 0 through 3.41
Vulnerable Versions Count92 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jan 6, 2026
  • Updated - Apr 8, 2026

Credits

  • Dmitrii Ignatyev (finder)

Website Distribution by Country

Number of websites using CVE-2025-14371
United States1,743 websites



Japan502 websites
Germany450 websites
Russia356 websites
France344 websites
Italy336 websites
GB120 websites
Spain109 websites
Poland91 websites
Netherlands88 websites

Website Distribution by TLD

Number of websites using CVE-2025-14371
.com2,310 websites
.net315 websites
.org276 websites
.ru260 websites
.it250 websites
.de239 websites
.fr133 websites
.jp115 websites
.info77 websites
.nl72 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-14371

Top websites that are affected by CVE-2025-14371. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.org United States*,***
*******.com United States*,***
***.********.com United States*,***
*********.com United States*,***
******.com United States*,***
****************.com United States*,***
****.org United States**,***
*********.com United States**,***
********.com United States**,***
******.com United States**,***
See full domain list

FAQ

CVE-2025-14371 is Missing Authorization in Simple Tags
A total of 5,216 websites have been identified as vulnerable to CVE-2025-14371, based on global website indexing conducted by WebTechSurvey.
The Simple Tags is affected by the CVE-2025-14371 vulnerability.
Simple Tags versions up to and including 3.41 are vulnerable to CVE-2025-14371.