F4 Media Taxonomies
F4 Media Taxonomies has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for F4 Media Taxonomies has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nabil Irawan. F4 Media Taxonomies is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-58617F4 Media Taxonomies <= 1.1.4 - Missing Authorization
Read the full analysisVulnerability Records

F4 Media Taxonomies
Author
FAKTOR VIER
F4 Media Taxonomies provides the ability to filter the media library by categories, tags and/or custom taxonomies. You can use the built-in taxonomies (category or post_tag) or any custom taxonomy. If a taxonomy is enabled for attachments, you can assign as many of their terms to an attachment as you need. You can assign them directly in the media library or in every media-selector overlay. There is also a nifty bulk function in the media library, which allows you to assign a single term to multiple attachments at once. Attachments can then be filtered by these terms. The filters are available in the media library and in every media-selector overlay. Different than other similar plugins, F4 Media Taxonomies is 100% free! Usage See FAQ for a guide how to enable categories, tags and custom taxonomies. Features overview Use any taxonomy (built-in or custom) Assign one or more terms to an attachment in media library/overlay Bulk assign terms to multiple attachments at once in media library Filter attachments by terms in media library/overlay Easy to use Lightweight and optimized 100% free!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C