CVE-2026-74012: WordPress TaxoPress plugin <= 3.51.0 - PHP Object Injection vulnerability
Published Aug 18, 2026
·Updated
Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.
Affected Software
1 affected component
WordPress TaxoPress Plugin<=3.51.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress TaxoPress pluginto a version that resolves this vulnerability.Fixed in 3.51.0
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations and users are in scope?
TaxoPress installations running version 3.51.0 or earlier are affected. Exploitation requires an authenticated user with Editor-level access.
2
What does an attacker need, and what is the potential impact?
The supplied CVSS vector indicates network-reachable exploitation with low attack complexity and no user interaction, but it requires low-level privileges. Successful exploitation can affect confidentiality, integrity, and availability.