CyberRota Analysis
AI-GeneratedThe Tag, Category, and Taxonomy Manager plugin for WordPress versions prior to 3.51.0 is vulnerable due to inadequate user authorization checks, enabling contributors to access and disclose information from private or draft posts they do not own. This flaw poses a significant risk to data confidentiality within WordPress sites, particularly for those managing sensitive content. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data leaks.
Original NVD Description
The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.