Low-privileged Control Panel users could create taxonomy terms by submitting requests to the field action processing endpoint with attacker-controlled field definitions. This bypasses the authorization checks enforced on the standard taxonomy term creation endpoint.
This has been fixed in 5.73.14 and 6.7.0.
{
"cwe_ids": [
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-18T20:00:51Z",
"nvd_published_at": "2026-03-20T22:16:29Z",
"severity": "MODERATE"
}