Taxopress is a niche WordPress taxonomy and content-organization plugin whose vulnerability profile, despite modest disclosure volume, reflects its role in the WordPress ecosystem and user-facing web interface. The recurring weaknesses—cross-site scripting, SQL injection, and missing authorization controls—are characteristic of WordPress plugins and recur across its web-handling and database-query surface. The plugin's vulnerabilities frequently acquire public exploit code, and defenders should monitor this vendor's releases and apply patches promptly to mitigate web-layer attack surface in WordPress deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Taxopress over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24444MEDIUM The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to se | Aug 2, 2021 | 4.8 | 28 | NO | YES |
CVE-2025-13359MEDIUM The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the "getTermsForAjax" function in all versio | Dec 3, 2025 | 6.5 | 23 | NO | NO |
CVE-2025-13354MEDIUM The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is | Dec 3, 2025 | 4.3 | 19 | NO | NO |
CVE-2023-2168MEDIUM The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Suggest Terms Title field in versions up to, and including, 3.6.4 due to insufficient input | Apr 19, 2023 | 4.8 | 18 | NO | NO |
CVE-2023-2170MEDIUM The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient inpu | Apr 19, 2023 | 4.8 | 15 | NO | NO |
CVE-2023-2169MEDIUM The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient inpu | Apr 19, 2023 | 4.8 | 15 | NO | NO |
The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege users | Apr 28, 2025 | 3.5 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Taxopress.
Media articles that mention a CVE ID that affects a product developed by Taxopress — matched by CVE ID, not by vendor name.