Vulnerabilities / Tainacan / WPSEC-2026-0674

Tainacan <= 1.3.0 - Authenticated (Editor+) Arbitrary File Read via Importer Source File

Medium 4.9 CWE-22Fixed in 1.4.0
ID
WPSEC-2026-0674
Plugin
Tainacan (tainacan)
Affected
all versions before 1.4.0
Remediation
Update to 1.4.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness
CWE-22
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
Tainacan on WPSec AttackSurface
Fix released
Published

Description

The Tainacan plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.3.0. The update handler of the importers REST endpoint called any importer setter named in the request body, including the one that sets the importer's source file path, and that path was not restricted to the uploads directory. This makes it possible for authenticated attackers with Tainacan management access, which the Editor role has by default, to read the contents of arbitrary files on the server, such as wp-config.php, through the importer's source preview and import.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0