Time-Based Blind SQL Injection in Tag, Category, and Taxonomy Manager β AI Autotagger with OpenAI for WordPress
CVE-2025-13922
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 December 2025
What is CVE-2025-13922?
The Tag, Category, and Taxonomy Manager β AI Autotagger with OpenAI plugin for WordPress suffers from a time-based blind SQL Injection vulnerability. This affects all versions leading up to and including 3.40.1. The vulnerability arises from inadequate sanitization of the 'existing_terms_orderby' parameter used in the AI preview AJAX endpoint. Authenticated users with Contributor-level access and appropriate AI metabox permissions can exploit this weakness by injecting malicious SQL queries into existing ones. This can lead to unauthorized data access, perform poorly on database operations, and enable attackers to infer sensitive information through timing side-channel attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Tag, Category, and Taxonomy Manager β AI Autotagger with OpenAI * <= 3.40.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved