WordPress Plugin Vulnerabilities

Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter

Description

The plugin does not properly escape one of its AJAX parameters before reflecting it in the response body served with an HTML content type, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of a logged-in user with `edit_pages` capability (Editor or higher) who is tricked into following a crafted link.

Proof of Concept

Affects Plugins

Fixed in 2.2.0

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Juyaz
Submitter
Juyaz
Verified
Yes

Timeline

Publicly Published
2026-06-29 (about 22 days ago)
Added
2026-06-29 (about 21 days ago)
Last Updated
2026-06-29 (about 21 days ago)

Other