Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPress simple-tags allows Blind SQL Injection.This issue affects TaxoPress: from n/a through <= 3.44.0.
Published: 2026-04-29
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of special characters in SQL commands allows an attacker to inject SQL through the TaxoPress plugin on WordPress sites. The flaw is a classic SQL injection (CWE‑89) and manifests as a blind injection, meaning the attacker may not see immediate error messages but can infer data through timing or other side channels. An attacker could extract sensitive database contents or alter data without authentication.

Affected Systems

All WordPress sites that have the TaxoPress simple‑tags plugin v3.44.0 or earlier installed are impacted. The plugin is authored by Steve Burge and the vulnerability spans all versions from the earliest available until 3.44.0 inclusive.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity vulnerability that can be exploited remotely via the web interface. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a web request sent to the plugin’s endpoints; an attacker with local network or internet access to the WordPress site can craft payloads that trigger blind SQL queries, eventually revealing or manipulating data. The lack of an immediate error response makes detection harder, increasing risk if the site is exposed.

Generated by OpenCVE AI on April 29, 2026 at 12:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the TaxoPress plugin to a version newer than 3.44.0
  • Configure a web application firewall to block suspicious SQL injection patterns targeting the simple‑tags endpoints
  • Review and restrict database user privileges and audit the plugin for other exposed inputs

Generated by OpenCVE AI on April 29, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Apr 2026 11:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPress simple-tags allows Blind SQL Injection.This issue affects TaxoPress: from n/a through <= 3.44.0.
Title WordPress TaxoPress plugin <= 3.44.0 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T11:59:41.328Z

Reserved: 2026-04-29T09:04:31.204Z

Link: CVE-2026-42646

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-04-29T12:16:19.927

Modified: 2026-04-29T21:15:41.667

Link: CVE-2026-42646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T13:00:06Z

Weaknesses