{
 "id": "WPSEC-2026-0673",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0673/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0673/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0673/index.md",
 "title": "Tainacan <= 1.3.0 - Authenticated (Subscriber+) Sensitive Information Exposure via Reports REST Endpoints",
 "description": "The Tainacan plugin for WordPress is vulnerable to Sensitive Information Exposure via the reports REST API endpoints in all versions up to, and including, 1.3.0. This is due to the endpoints' permission callback only checking for the 'read' capability, while the activity reports returned the usernames, first and last names, and email addresses of users who performed actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve repository reports and personal data of staff accounts.",
 "plugin": {
  "slug": "tainacan",
  "name": "Tainacan",
  "full_name": "Tainacan",
  "wordpress_org": "https://wordpress.org/plugins/tainacan/",
  "advisories_url": "https://wpsec.com/vuln/plugin/tainacan/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/tainacan"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "0.18",
    "from_inclusive": true,
    "to": "1.4.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 0.18 before 1.4.0"
  ]
 },
 "introduced_in": "0.18",
 "fixed_in": "1.4.0",
 "remediation": "Update to 1.4.0 or later.",
 "fix_released": "2026-10-07T18:34:39+00:00",
 "published": "2026-10-08T18:42:43+00:00",
 "updated": "2026-10-08T07:41:04.537138+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0673/",
  "https://plugins.svn.wordpress.org/tainacan/tags/1.4.0/",
  "https://wordpress.org/plugins/tainacan/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/tainacan",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}