Time-Based Blind SQL Injection in Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI for WordPress
CVE-2025-13922

6.5MEDIUM

What is CVE-2025-13922?

The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress suffers from a time-based blind SQL Injection vulnerability. This affects all versions leading up to and including 3.40.1. The vulnerability arises from inadequate sanitization of the 'existing_terms_orderby' parameter used in the AI preview AJAX endpoint. Authenticated users with Contributor-level access and appropriate AI metabox permissions can exploit this weakness by injecting malicious SQL queries into existing ones. This can lead to unauthorized data access, perform poorly on database operations, and enable attackers to infer sensitive information through timing side-channel attacks.

Affected Version(s)

Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI * <= 3.40.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.
CVE-2025-13922 : Time-Based Blind SQL Injection in Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI for WordPress