The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the taxopress_ai_add_post_term function in all versions up to, and including, 3.41.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to add or remove taxonomy terms (tags, categories) on any post, including ones they do not own.
We have discovered 5,216 live websites that are affected by CVE-2025-14371.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 5,216 live websites (41% of Simple Tags install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 92 versions ( 97% of all versions) |
| 1,743 websites | |
| 502 websites | |
| 450 websites | |
| 356 websites | |
| 344 websites | |
| 336 websites | |
| 120 websites | |
| 109 websites | |
| 91 websites | |
| 88 websites |
| .com | 2,310 websites |
| .net | 315 websites |
| .org | 276 websites |
| .ru | 260 websites |
| .it | 250 websites |
| .de | 239 websites |
| .fr | 133 websites |
| .jp | 115 websites |
| .info | 77 websites |
| .nl | 72 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.org | *,*** | ||
| *******.com | *,*** | ||
| ***.********.com | *,*** | ||
| *********.com | *,*** | ||
| ******.com | *,*** | ||
| ****************.com | *,*** | ||
| ****.org | **,*** | ||
| *********.com | **,*** | ||
| ********.com | **,*** | ||
| ******.com | **,*** |
FAQ