CVE-2025-14371: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14371 is a missing authorization vulnerability in the TaxoPress: Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress. It affects all versions up to and including 3.41.0, allowing authenticated attackers with Contributor-level access or above to add or remove taxonomy terms (tags, categories) on any post, including posts they do not own. The vulnerability was disclosed on January 6, 2026, with a patch available in version 3.41.1. It carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Wordfence (Wordfence, Feedly).

Technical details

The root cause is a missing capability check (CWE-862) on the taxopress_ai_add_post_term function within the plugin's AJAX handler class (TaxoPressAiAjax.php). Because no authorization check verifies whether the requesting user has permission to modify a given post's taxonomy terms, any authenticated user with at least Contributor-level access can invoke this function via a network request. The vulnerable code is visible in the plugin's source at line 681 of TaxoPressAiAjax.php in version 3.40.1 (WordPress Trac). A technical write-up is also available from CleanTalk Research (CleanTalk).

Impact

Successful exploitation allows an authenticated attacker to arbitrarily add or remove tags and categories on any WordPress post, regardless of post ownership. This compromises content integrity across the site — for example, an attacker could strip important categories from posts, inject misleading tags, or disrupt SEO-critical taxonomy structures. There is no confidentiality or availability impact; the vulnerability is limited to unauthorized data modification (Wordfence, Feedly).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a valid Contributor-level WordPress account on the target site, limiting the attack surface (Feedly, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify a WordPress site running the TaxoPress AI Autotagger plugin at version 3.41.0 or earlier, and obtain or register a Contributor-level (or higher) account on the target site.
  2. Identify the vulnerable AJAX endpoint: Locate the WordPress AJAX action associated with the taxopress_ai_add_post_term function, which is exposed without a capability check.
  3. Craft a malicious request: As an authenticated Contributor, send a crafted HTTP POST request to the WordPress AJAX handler (e.g., wp-admin/admin-ajax.php) with the appropriate action parameter and a target post ID belonging to another user.
  4. Modify taxonomy terms: Include the desired taxonomy term (tag or category) in the request payload to add or remove it from the target post, bypassing any ownership or permission validation.
  5. Achieve objective: Confirm that the taxonomy terms on the victim post have been altered, achieving unauthorized content modification (WordPress Trac, CleanTalk).

Indicators of compromise

  • Logs: WordPress access logs showing repeated POST requests to wp-admin/admin-ajax.php with the TaxoPress AI action parameter from Contributor-level user accounts, especially targeting post IDs not owned by those users.
  • Application Logs: Unexpected taxonomy term changes (tag/category additions or removals) on posts not authored by the modifying user, visible in WordPress post revision or audit logs if audit logging is enabled.
  • Behavioral: Multiple posts across the site experiencing unexplained taxonomy changes within a short time window, particularly if correlated with a single low-privileged user account.

Mitigation and workarounds

Users should update the TaxoPress plugin to version 3.41.1 or later, which introduces the missing capability check and resolves the vulnerability. No configuration-based workaround is available short of disabling the plugin entirely. Site administrators should also audit recent taxonomy changes on posts to identify any unauthorized modifications made prior to patching (Wordfence, Feedly).

Community reactions

Wordfence, which discovered and reported the vulnerability, published a threat intelligence entry covering the issue. Sucuri included CVE-2025-14371 in its January 2026 vulnerability patch roundup, noting it as part of a broader set of WordPress plugin issues requiring attention (Sucuri Blog). Community coverage has been limited given the medium severity and low exploitation probability.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management