SensitiveTagCloud
SensitiveTagCloud has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for SensitiveTagCloud has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Skalucy. SensitiveTagCloud is installed on roughly 40 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 2.99999.
CVE-2025-49344SensitiveTagCloud <= 1.4.1 - Cross-Site Request Forgery
Read the full analysisVulnerability Records
SensitiveTagCloud
Author
reneade
This wordpress plugin provides a configurable tagcloud that shows tags depending of the current context only. For example the tagcloud shows only tags that really occur in the current category, or within the current date-, author-, tag- archive or even only the tags that occur in the search results. It is also possible to restrict the links of the tag cloud to the current viewing tag archive or category: If you click on the tag “test1” within the tag cloud of the tag archive of “test2” the target page will only contain posts that have both tags, like a drill down navigation. It is possible to exclude the tag of the tag-archive itself from the tagcloud. For the single post pages you can configure the tagcloud to show also related tags of the current posts, not only the direct tags of the post. And you can configure the tagcloud to exclude the tag of the current post, to show only the related tags. The style and sizes of the tagcloud can be configured, and the widget can be configured to be only visible if viewing a tag archive, category, a sinlge post or even only if viewing the searchresults for example. It is also possible to configure the number of tags that should be displayed in the different conditions. Plugin Website: http://www.rene-ade.de/inhalte/wordpress-plugin-sensitivetagcloud.html Donations: http://www.rene-ade.de/stichwoerter/spenden Update Deactivate the Plugin Remove the existing folder ‘sensitive-tag-cloud’ with all files from the ‘wp-content/plugins’ folder on your webserver Upload the new folder ‘sensitive-tag-cloud’ with all files to ‘/wp-content/plugins’ on your webserver Activate the plugin through the ‘Plugins’ menu in WordPress
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C