TaxoPress Plugin for WordPress Authorization Bypass Vulnerability (CVE-2025-13354) — Medium Severity

Overview

A security flaw has been found in the TaxoPress plugin for WordPress, a popular tool for managing tags, categories, and other taxonomy terms. This vulnerability, identified as an authorization bypass, allows attackers with even low-level access to your WordPress site (like a subscriber) to merge or delete taxonomy terms without proper permission. This means an unauthorized user could potentially tamper with how your content is organized, affecting site navigation and SEO.

CVE Details

  • Product: TaxoPress plugin for WordPress (Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI)
  • CVE ID: CVE-2025-13354
  • Published Date: December 3, 2025
  • Severity: Medium
  • Status: Analyzed

Affected Products

The vulnerability affects all versions of the TaxoPress plugin for WordPress up to, and including, version 3.40.1. If you are running any version within this range, your website could be at risk.

Current Status

This vulnerability has been officially analyzed. The developers of TaxoPress have addressed this issue in a subsequent release. The fix involves adding proper authorization checks within the taxopress_merge_terms_batch function, ensuring that only authorized users can perform sensitive actions like merging or deleting taxonomy terms.

Severity Level

The vulnerability is rated as “Medium” severity. While it requires an authenticated user, even a subscriber-level account can exploit it. The ability to manipulate taxonomy terms could lead to:

  • Content Disruption: Incorrectly categorized or missing content, making it difficult for visitors to find information.
  • SEO Impact: Damaged search engine rankings due to altered URLs or content structure.
  • Reputational Damage: A compromised website can erode user trust.

Although direct remote code execution or data theft might not be possible, the impact on content integrity and site functionality makes this a significant concern for website administrators.

Possible Solutions

To protect your WordPress website from CVE-2025-13354, it is crucial to update your TaxoPress plugin immediately.

  1. Update the Plugin: Upgrade your TaxoPress plugin to version 3.40.2 or the latest available version that includes the patch. Always back up your website before performing any updates.
  2. Regular Updates: Keep all your WordPress themes, plugins, and core installation up to date to ensure you have the latest security fixes.
  3. Principle of Least Privilege: Ensure that user accounts have only the minimum necessary permissions to perform their tasks. For instance, if a user doesn’t need to manage taxonomy terms, they shouldn’t have that capability.

References

https://github.com/TaxoPress/TaxoPress/commit/5eb2cee861ebd109152eea968aca0259c078c8b0
https://www.wordfence.com/threat-intel/vulnerabilities/id/05c1ee52-02c9-440b-9269-14ea8b73be45?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.