Impact
The WordPress plugin Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI contains a time‑based blind SQL injection flaw in the AI preview AJAX endpoint. The vulnerable "existing_terms_orderby" parameter is not properly escaped or parameterized, allowing an attacker to append additional SQL to an existing query. This weakness can be leveraged to extract sensitive database information, degrade database performance, or infer data through timing attacks. The flaw is a classic SQL injection (CWE-89) and therefore threatens confidentiality, integrity, and availability.
Affected Systems
The flaw affects the Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress. All releases up to and including version 3.40.1 are vulnerable. No other vendors or product lines are listed, so the impact is limited to installations of this plugin.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests current exploitation probability is low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with Contributor or higher privileges who also has AI metabox permissions, making the attack vector web‑based and dependent on user roles. Once these prerequisites are met, an attacker can perform time‑based blind SQL injection, potentially accessing confidential data or causing noticeable performance issues.
OpenCVE Enrichment