Time-Based Blind SQL Injection in Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI for WordPress
CVE-2025-13922
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 December 2025
What is CVE-2025-13922?
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress suffers from a time-based blind SQL Injection vulnerability. This affects all versions leading up to and including 3.40.1. The vulnerability arises from inadequate sanitization of the 'existing_terms_orderby' parameter used in the AI preview AJAX endpoint. Authenticated users with Contributor-level access and appropriate AI metabox permissions can exploit this weakness by injecting malicious SQL queries into existing ones. This can lead to unauthorized data access, perform poorly on database operations, and enable attackers to infer sensitive information through timing side-channel attacks.
Affected Version(s)
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI * <= 3.40.1