PT-2025-47696 · WordPress · Tainacan
Deadbee
·
Published
2025-11-21
·
Updated
2026-01-26
·
CVE-2025-12746
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tainacan versions prior to 1.0.1
Description
The Tainacan plugin for WordPress is susceptible to Reflected Cross-Site Scripting. This is due to insufficient input sanitization and output escaping in the
search parameter. An unauthenticated attacker can inject arbitrary web scripts into pages, which will execute if a user is tricked into performing an action, such as clicking a link. The API endpoint affected is not specified. The vulnerable parameter is search.Recommendations
Update Tainacan to version 1.0.1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tainacan