The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are available for all roles. As a result, any authenticated user (including simple subscribers) can add/set/delete arbitrary categories to posts.
https://wpscan.com/vulnerability/f8fdff8a-f158-46e8-94f1-f051a6c5608b