DynamicTags
DynamicTags has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 6.5 out of 10.
The most common weakness is SQL Injection, behind 1 of the records (100%).
The one issue recorded for DynamicTags has a vendor fix available, so running the current release closes it.
All of these findings were reported by João Pedro Soares de Alcântara. DynamicTags is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-22348DynamicTags <= 1.4.0 - Authenticated (Subscriber+) SQL Injection
Read the full analysisVulnerability Records

DynamicTags
Author
rtowebsites
Dynamic Tags is an Elementor addon that adds some useful dynamic tags. The plugin requires Elementor Pro since it uses Dynamic Tags to set the comparison conditions. It provides the following tags: Text-Tags Acf Repeater (returns content of an acf-repeater field) Cookies (you can select between all set cookies) Session (you can select between all set session keys) Current-Language (returns current language from WPML or Polylang) Current-Url (returns the actually called url) NumberPostsQuery (return number of posts with a custom query) PodsExtended (supports yes/no fields of pods) Server Vars (returns content of $_SERVER PHP-Variable) User/Author Image (returns the user/author image-url or false if not found) User Role (returns a comma-separated list of current user roles) WidgetContent (returns content of a widget selected by widget-id) Post Tags Post Content Post Parent Post Status Post Type Yes/no tags Are Comments allowed Current User Can (can check, for example if user can edit_posts) Is author of post Is feed Is Frontpage Is Home Is Post in category Is Post in list Is Singular
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C