CVE-2025-13354: Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI <= 3.40.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Taxonomy Term Manipulation
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.40.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the "taxopressmergetermsbatch" function. This makes it possible for authenticated attackers, with subscriber level access and above, to merge or delete arbitrary taxonomy terms.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13354?
CVE-2025-13354 has been classified with a high severity due to its potential for unauthorized access.
How do I fix CVE-2025-13354?
To fix CVE-2025-13354, update the Tag, Category, and Taxonomy Manager – AI Autotagger to version 3.40.2 or later.
What type of vulnerability is identified in CVE-2025-13354?
CVE-2025-13354 is an authorization bypass vulnerability that allows unauthorized actions.
Which versions are affected by CVE-2025-13354?
All versions of the Tag, Category, and Taxonomy Manager – AI Autotagger up to and including version 3.40.1 are affected by CVE-2025-13354.
Who is the vendor for the plugin related to CVE-2025-13354?
The vendor for the plugin related to CVE-2025-13354 is AI Autotagger.