PT-2025-52573 · WordPress · Tainacan

Deadbee

·

Published

2025-12-21

·

Updated

2025-12-21

·

CVE-2025-14043

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tainacan plugin for WordPress versions up to and including 1.0.1
Description The Tainacan plugin for WordPress has a flaw where unauthorized metadata sections can be created. This is because the create item permissions check() function always returns true, bypassing necessary authentication and authorization checks. This allows unauthenticated attackers to create arbitrary metadata sections for any collection through the public REST API, provided they have access to the WordPress site.
Recommendations Update the Tainacan plugin to a version beyond 1.0.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14043

Affected Products

Tainacan