Auto Tag Creator
Auto Tag Creator has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Auto Tag Creator has a vendor fix available, so running the current release closes it.
All of these findings were reported by Abdi Pranata. Auto Tag Creator is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2023-47523Auto Tag Creator <= 1.0.2 - Missing Authorization via tag_save_settings_callback
Read the full analysisVulnerability Records
Auto Tag Creator
Author
Ecreate Infotech
This plugin automatically converts keywords in a post/product title and category to tags upon saving. It includes a user-editable list of words you want the plugin to ignore Converts keywords in post/product titles to tags Converts keywords in post/product category to tags Includes user-editable list of words to be ignored Setting to enable for title and category separately Setting to overwrite previous tag and consider only title and category while generating new one Converts on publish and update. Multi-blog adminstrators take note: this plugin is especially helpful if you’re building a community-based site where tagging is important and your bloggers are not always diligent about tagging.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C