Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Taxopress

First CVE: Aug 2, 2021Active for: 5 yearsTotal CVEs: 7

Taxopress is a niche WordPress taxonomy and content-organization plugin whose vulnerability profile, despite modest disclosure volume, reflects its role in the WordPress ecosystem and user-facing web interface. The recurring weaknesses—cross-site scripting, SQL injection, and missing authorization controls—are characteristic of WordPress plugins and recur across its web-handling and database-query surface. The plugin's vulnerabilities frequently acquire public exploit code, and defenders should monitor this vendor's releases and apply patches promptly to mitigate web-layer attack surface in WordPress deployments; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
4.8
Avg CVSS Score
Higher Avg CVSS Score than 8% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Taxopress over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2021
4 years ago
Most Recent CVE
Dec 3, 2025
237 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-24444MEDIUM
The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Taxonomy description field, allowing high privilege users to se
Aug 2, 20214.828NOYES
CVE-2025-13359MEDIUM
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based SQL Injection via the "getTermsForAjax" function in all versio
Dec 3, 20256.523NONO
CVE-2025-13354MEDIUM
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is
Dec 3, 20254.319NONO
CVE-2023-2168MEDIUM
The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Suggest Terms Title field in versions up to, and including, 3.6.4 due to insufficient input
Apr 19, 20234.818NONO
CVE-2023-2170MEDIUM
The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient inpu
Apr 19, 20234.815NONO
CVE-2023-2169MEDIUM
The TaxoPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Related Posts functionality in versions up to, and including, 3.6.4 due to insufficient inpu
Apr 19, 20234.815NONO
CVE-2025-0627LOW
The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege users
Apr 28, 20253.514NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
14%
86%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
LowMedium
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (28.6%)
Unknown0 (0.0%)
Required5 (71.4%)
Privileges Required
Low2 (28.6%)
High5 (71.4%)
None0 (0.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Taxopress.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Taxopress — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Taxopress's Products

View all 2 CNAs →

Top CWEs