CVE-2025-0627
CVSS 3.1 Score 3.5 of 10 (low)
Details
Published Apr 28, 2025
Updated: Apr 30, 2025
CWE ID 79
Summary
CVE-2025-0627 is a vulnerability affecting the WordPress Tag, Category, and Taxonomy Manager plugin. This issue allows high privilege users, including admins, to execute Stored Cross-Site Scripting attacks. Despite the disallowance of the unfiltered_html capability, especially in multisite setups, the plugin fails to sanitize and escape some widget settings. This security flaw poses a significant risk to WordPress websites using the affected plugin version before 3.30.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Taxopress
Affected Vendors
- Taxopress