CVE-2026-74012

WordPress TaxoPress plugin <= 3.51.0 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0.


We have discovered 13,221 live websites that are affected by CVE-2026-74012.

Run a Free Instant Scan




Affected Software

Product  Simple Tags
Category Wordpress Plugins
Vulnerable Domains13,221 live websites (100% of Simple Tags install base)
Vulnerable Versions
  • from 0 through 3.51
Vulnerable Versions Count97 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-502 Deserialization of Untrusted Data



Details

  • Published - Aug 18, 2026
  • Updated - Aug 20, 2026

Credits

  • daroo | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-74012
United States4,129 websites



Japan1,915 websites
Germany1,196 websites
France867 websites
Italy825 websites
Russia501 websites
GB410 websites
Spain270 websites
Netherlands269 websites
Canada204 websites

Website Distribution by TLD

Number of websites using CVE-2026-74012
.com5,668 websites
.org833 websites
.net801 websites
.de706 websites
.it552 websites
.fr420 websites
.jp390 websites
.ru386 websites
.nl214 websites
.info200 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-74012

Top websites that are affected by CVE-2026-74012. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.org United States*,***
****.org GB*,***
*********.com United States*,***
******.com United States*,***
*******.org Austria**,***
**********.com United States**,***
****.org United States**,***
*************.edu United States**,***
*********.com United States**,***
********.com United States**,***
See full domain list

FAQ

CVE-2026-74012 is Deserialization of Untrusted Data in Simple Tags
A total of 13,221 websites have been identified as vulnerable to CVE-2026-74012, based on global website indexing conducted by WebTechSurvey.
The Simple Tags is affected by the CVE-2026-74012 vulnerability.
Simple Tags versions up to and including 3.51 are vulnerable to CVE-2026-74012.