DynamicTags

DynamicTags has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 6.5 out of 10.

The most common weakness is SQL Injection, behind 1 of the records (100%).

The one issue recorded for DynamicTags has a vendor fix available, so running the current release closes it.

All of these findings were reported by João Pedro Soares de Alcântara. DynamicTags is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all DynamicTags vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.5CVE-2025-22348

DynamicTags <= 1.4.0 - Authenticated (Subscriber+) SQL Injection

Read the full analysis

Vulnerability Records

1 records
DynamicTags banner
Latestv1.4.1
4.3(9)
86/100
Last Updated
2025-02-11 (2y ago)
Active Installs
2,000+
Downloads
50,173
Requires WP
5.0+
Requires PHP
7.4+
Tested up to
WP 6.7.7
Created
2020-08-14 (6y ago)

Dynamic Tags is an Elementor addon that adds some useful dynamic tags. The plugin requires Elementor Pro since it uses Dynamic Tags to set the comparison conditions. It provides the following tags: Text-Tags Acf Repeater (returns content of an acf-repeater field) Cookies (you can select between all set cookies) Session (you can select between all set session keys) Current-Language (returns current language from WPML or Polylang) Current-Url (returns the actually called url) NumberPostsQuery (return number of posts with a custom query) PodsExtended (supports yes/no fields of pods) Server Vars (returns content of $_SERVER PHP-Variable) User/Author Image (returns the user/author image-url or false if not found) User Role (returns a comma-separated list of current user roles) WidgetContent (returns content of a widget selected by widget-id) Post Tags Post Content Post Parent Post Status Post Type Yes/no tags Are Comments allowed Current User Can (can check, for example if user can edit_posts) Is author of post Is feed Is Frontpage Is Home Is Post in category Is Post in list Is Singular

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C