PT-2025-47786 · WordPress · Tainacan

Deadbee

·

Published

2025-11-21

·

Updated

2025-11-22

·

CVE-2025-12747

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tainacan plugin for WordPress versions up to and including 1.0.0
Description The Tainacan plugin for WordPress has an information exposure issue in versions up to and including 1.0.0. Uploaded files marked as private are exposed in the wp-content directory without sufficient protection, potentially allowing unauthenticated attackers to extract sensitive information.
Recommendations Update the Tainacan plugin to a version newer than 1.0.0.

Fix

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2025-12747

Affected Products

Tainacan