plugin

Tainacan Vulnerabilities

32 known security issues reported for the Tainacan WordPress plugin. Most recent disclosed Jul 7, 2026.

4 high 13 medium

Running Tainacan on your site? Check whether your installed version is affected.

Scan your site free

Tainacan <= 1.0.3 - Unauthenticated SQL Injection via 'geoquery' REST API Parameter

high

The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated at...

CVSS:
7.5
Affected:
up to 1.0.3
Fixed in:
1.1.0
Disclosed:
Jul 7, 2026

CVE-2026-6230 on NVD →

Tainacan <= 1.0.3 - Unauthenticated SQL Injection

high

The Tainacan plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into al...

CVSS:
7.5
Affected:
up to 1.0.3
Fixed in:
1.1.0
Disclosed:
May 28, 2026

CVE-2026-42740 on NVD →

Tainacan [tainacan] < 1.0.2

unknown

[en] The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization checks in all versions up to, and including, 1.0.1. This is due to the `create_item_permissions_check()` function unconditionally returning true, which bypasses authentication and authorization va...

Affected:
up to 1.0.2
Fixed in:
1.0.2
Disclosed:
Dec 21, 2025

CVE-2025-14043 on NVD →

Tainacan <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Metadata Section Creation

medium

The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization checks in all versions up to, and including, 1.0.1. This is due to the `create_item_permissions_check()` function unconditionally returning true, which bypasses authentication and authorization validat...

CVSS:
5.3
Affected:
up to 1.0.1
Fixed in:
1.0.2
Disclosed:
Dec 20, 2025

CVE-2025-14043 on NVD →

Tainacan [tainacan] < 1.0.1 (closed)

unknown

[en] The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...

Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
Nov 21, 2025

CVE-2025-12746 on NVD →

Tainacan [tainacan] < 1.0.1 (closed)

unknown

[en] The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via uploaded files marked as private being exposed in wp-content without adequate protection. This makes it possible for unauthenticated attackers to extract potentially sensitive information from f...

Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
Nov 21, 2025

CVE-2025-12747 on NVD →

Tainacan <= 1.0.0 - Reflected Cross-Site Scripting

medium

The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 1.0.0
Fixed in:
1.0.1
Disclosed:
Nov 20, 2025

CVE-2025-12746 on NVD →

Tainacan <= 1.0.0 - Unauthenticated Information Exposure

medium

The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via uploaded files marked as private being exposed in wp-content without adequate protection. This makes it possible for unauthenticated attackers to extract potentially sensitive information from files...

CVSS:
5.3
Affected:
up to 1.0.0
Fixed in:
1.0.1
Disclosed:
Nov 20, 2025

CVE-2025-12747 on NVD →

Tainacan [tainacan] < 0.21.15 (closed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tainacan Tainacan allows Path Traversal. This issue affects Tainacan: from n/a through 0.21.14.

Affected:
up to 0.21.15
Fixed in:
0.21.15
Disclosed:
May 23, 2025

CVE-2025-47512 on NVD →

Tainacan <= 0.21.14 - Unauthenticated Arbitrary File Deletion

medium

The Tainacan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 0.21.14. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right f...

CVSS:
5.3
Affected:
up to 0.21.14
Fixed in:
0.21.15
Disclosed:
May 16, 2025

CVE-2025-47512 on NVD →

Tainacan [tainacan] < 0.21.13 (closed)

unknown

[en] The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to, and including, 0.21.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attack...

Affected:
up to 0.21.13
Fixed in:
0.21.13
Disclosed:
Jan 23, 2025

CVE-2024-13236 on NVD →

Tainacan <= 0.21.12 - Authenticated (Subscriber+) SQL Injection

medium

The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to, and including, 0.21.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,...

CVSS:
6.5
Affected:
up to 0.21.12
Fixed in:
0.21.13
Disclosed:
Jan 22, 2025

CVE-2024-13236 on NVD →

Tainacan [tainacan] < 0.21.9 (closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tainacan.Org Tainacan allows SQL Injection.This issue affects Tainacan: from n/a through 0.21.8.

Affected:
up to 0.21.9
Fixed in:
0.21.9
Disclosed:
Oct 11, 2024

CVE-2024-48040 on NVD →

Tainacan [tainacan] < 0.21.11 (closed)

unknown

[en] The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 0.21.10. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

Affected:
up to 0.21.11
Fixed in:
0.21.11
Disclosed:
Oct 11, 2024

CVE-2024-9221 on NVD →

Tainacan <= 0.21.10 - Reflected Cross-Site Scripting

medium

The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 0.21.10. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...

CVSS:
6.1
Affected:
up to 0.21.10
Fixed in:
0.21.11
Disclosed:
Oct 10, 2024

CVE-2024-9221 on NVD →

Tainacan <= 0.21.8 - Authenticated (Subscriber+) SQL Injection

medium

The Tainacan plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.21.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above,...

CVSS:
6.5
Affected:
up to 0.21.8
Fixed in:
0.21.9
Disclosed:
Oct 9, 2024

CVE-2024-48040 on NVD →

Tainacan [tainacan] < 0.21.8 (closed)

unknown

[en] The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with Subscriber-level...

Affected:
up to 0.21.8
Fixed in:
0.21.8
Disclosed:
Jul 31, 2024

CVE-2024-7135 on NVD →

Tainacan <= 0.21.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read

medium

The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with Subscriber-level acce...

CVSS:
6.5
Affected:
up to 0.21.7
Fixed in:
0.21.8
Disclosed:
Jul 30, 2024

CVE-2024-7135 on NVD →

Tainacan [tainacan] < 0.20.8 (closed)

unknown

[en] Missing Authorization vulnerability in Tainacan.Org Tainacan.This issue affects Tainacan: from n/a through 0.20.7.

Affected:
up to 0.20.8
Fixed in:
0.20.8
Disclosed:
Jun 9, 2024

CVE-2024-30529 on NVD →

Tainacan [tainacan] < 0.21.4 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tainacan.Org Tainacan allows Reflected XSS.This issue affects Tainacan: from n/a through 0.21.3.

Affected:
up to 0.21.4
Fixed in:
0.21.4
Disclosed:
Jun 3, 2024

CVE-2024-34794 on NVD →

Tainacan [tainacan] < 0.21.4 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tainacan.Org Tainacan allows Stored XSS.This issue affects Tainacan: from n/a through 0.21.3.

Affected:
up to 0.21.4
Fixed in:
0.21.4
Disclosed:
Jun 3, 2024

CVE-2024-34795 on NVD →

Tainacan <= 0.21.3 - Unauthenticated Stored Cross-Site Scripting

high

The Tainacan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 0.21.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...

CVSS:
7.2
Affected:
up to 0.21.3
Fixed in:
0.21.4
Disclosed:
May 20, 2024

CVE-2024-34794 on NVD →

PDF.js < 4.2.67 - Arbitrary JavaScript Execution

medium

PDF.js is vulnerable to Arbitrary JavaScript Execution in versions prior to 4.2.67. This is due to a missing type check when handling fonts. This makes it possible for authenticated attackers, with contributor-level or above permissions, to execute arbitrary JavaScript if they can successfully trick a user into opening...

CVSS:
6.4
Affected:
up to 0.21.5
Fixed in:
0.21.6
Disclosed:
May 20, 2024

CVE-2024-4367 on NVD →

Tainacan <= 0.21.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Tainacan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.21.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to 0.21.3
Fixed in:
0.21.4
Disclosed:
May 20, 2024

CVE-2024-34795 on NVD →

Tainacan [tainacan] < 0.21.6 (closed)

unknown

[en] A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

Affected:
up to 0.21.6
Fixed in:
0.21.6
Disclosed:
May 14, 2024

CVE-2024-4367 on NVD →

Tainacan <= 0.20.7 - Missing Authorization

medium

The Tainacan plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in versions up to, and including, 0.20.7. This makes it possible for unauthenticated attackers to perform unauthorized actions.

CVSS:
5.3
Affected:
up to 0.20.7
Fixed in:
0.20.8
Disclosed:
Mar 29, 2024

CVE-2024-30529 on NVD →

Tainacan [tainacan] < 0.20.7 (closed)

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Tainacan.Org Tainacan.This issue affects Tainacan: from n/a through 0.20.6.

Affected:
up to 0.20.7
Fixed in:
0.20.7
Disclosed:
Feb 29, 2024

CVE-2024-1435 on NVD →

Tainacan <= 0.20.6 - Unauthenticated Sensitive Information Exposure

medium

The Tainacan plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.20.6. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 0.20.6
Fixed in:
0.20.7
Disclosed:
Feb 26, 2024

CVE-2024-1435 on NVD →

Tainacan [tainacan] < 0.20.5 (closed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tainacan.Org Tainacan allows Reflected XSS.This issue affects Tainacan: from n/a through 0.20.4.

Affected:
up to 0.20.5
Fixed in:
0.20.5
Disclosed:
Nov 30, 2023

CVE-2023-47848 on NVD →

Tainacan <= 0.20.4 - Reflected Cross-Site Scripting

medium

The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.20.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

CVSS:
6.1
Affected:
up to 0.20.4
Fixed in:
0.20.5
Disclosed:
Nov 20, 2023

CVE-2023-47848 on NVD →

Tainacan <= 0.18.9 - Cross-Site Scripting

high

The plugin Tainacan for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.18.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS:
7.2
Affected:
up to 0.18.9
Fixed in:
0.18.10
Disclosed:
May 24, 2022

Tainacan [tainacan] < 0.18.10 (closed)

unknown

The plugin Tainacan for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.18.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Affected:
up to 0.18.10
Fixed in:
0.18.10
Disclosed:
May 24, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database