Description
Insertion of Sensitive Information Into Sent Data vulnerability in Steve Burge TaxoPress simple-tags allows Retrieve Embedded Sensitive Data.This issue affects TaxoPress: from n/a through <= 3.37.2.
Published: 2025-08-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Steve Burge TaxoPress WordPress plugin allows sensitive information to be inserted into data that is then transmitted. An attacker who succeeds in triggering this behavior can retrieve embedded sensitive data from the plugin’s output, effectively compromising the confidentiality of information that was not intended for exposure. The weakness is identified as CWE‑201, a Sensitive Information Exposure flaw, and the available CVSS score of 4.3 reflects a low‑to‑moderate overall severity.

Affected Systems

WordPress sites that have the TaxoPress plugin version 3.37.2 or earlier installed are affected. The vulnerability applies to all releases from the plugin’s earliest public version through 3.37.2. This includes sites using the simple‑tags feature of TaxoPress to manage taxonomy tags.

Risk and Exploitability

The CSVS score of 4.3 places the issue in the medium risk range, but the EPSS score of less than 1 % indicates that exploitation is currently expected to be rare. The vulnerability is not listed in the CISA KEV catalog, further suggesting it is not actively exploited in the wild. The attack vector is not explicitly documented, but the language of the description implies an exploit may be carried out by feeding crafted input to the plugin that causes it to embed sensitive data into sent responses. If an attacker can deliver such input—likely through a web request to the WordPress installation—the exposed data could be read by the attacker or a third party.

Generated by OpenCVE AI on April 30, 2026 at 03:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update TaxoPress to a release newer than 3.37.2, which contains the fix for the sensitive data exposure flaw.
  • Check the site’s plugin files for any unauthorized modifications or additional code that may be injecting sensitive data, and remove or audit such code.
  • Apply general WordPress hardening practices, such as restricting access to plugin administration pages, enforcing least‑privilege for users, and monitoring traffic for anomalous data transmissions that could indicate exploitation.

Generated by OpenCVE AI on April 30, 2026 at 03:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-24923 Insertion of Sensitive Information Into Sent Data vulnerability in Steve Burge TaxoPress allows Retrieve Embedded Sensitive Data. This issue affects TaxoPress: from n/a through 3.37.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in Steve Burge TaxoPress allows Retrieve Embedded Sensitive Data. This issue affects TaxoPress: from n/a through 3.37.2. Insertion of Sensitive Information Into Sent Data vulnerability in Steve Burge TaxoPress simple-tags allows Retrieve Embedded Sensitive Data.This issue affects TaxoPress: from n/a through <= 3.37.2.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Taxopress
Taxopress taxopress
Wordpress
Wordpress wordpress
Vendors & Products Taxopress
Taxopress taxopress
Wordpress
Wordpress wordpress

Thu, 14 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 18:30:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in Steve Burge TaxoPress allows Retrieve Embedded Sensitive Data. This issue affects TaxoPress: from n/a through 3.37.2.
Title WordPress TaxoPress Plugin <= 3.37.2 - Sensitive Data Exposure Vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Taxopress Taxopress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:37.201Z

Reserved: 2025-08-14T09:10:30.442Z

Link: CVE-2025-55710

cve-icon Vulnrichment

Updated: 2025-08-14T19:35:11.279Z

cve-icon NVD

Status : Deferred

Published: 2025-08-14T19:15:43.027

Modified: 2026-04-23T15:32:56.287

Link: CVE-2025-55710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T03:30:27Z

Weaknesses