Executive brief
A vulnerability in the Tag Groups WordPress plugin, which is used to organize and display website categories and tags, could allow an attacker to take control of a site administrator's session. By tricking a user with high-level permissions (like an Editor) into clicking a malicious link, an attacker can execute unauthorized commands on the website. This could lead to unauthorized content changes or full site compromise depending on the victim's access level.
Technical details
The Tag Groups plugin for WordPress fails to properly sanitize and escape the 'tag_groups_task' AJAX parameter before reflecting it back in an HTML response. This results in a reflected cross-site scripting (XSS) vulnerability (CWE-79). An unauthenticated attacker can exploit this by crafting a malicious URL and social engineering a user with 'edit_pages' capabilities (Editor or higher) into clicking it. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser session, which can be used to perform administrative actions or steal session cookies. The issue is resolved in version 2.2.0.
Affected products
- Unknown Tag Groups is the Advanced Way to Display Your Taxonomy Terms < 2.2.0
Timeline
- 2026-06-29: disclosed: Publicly published by WPScan
- 2026-06-29: patched: Fixed in version 2.2.0
- 2026-07-20: advisory: NVD publication date