Vulnerabilities / Tainacan / WPSEC-2026-0674
Tainacan <= 1.3.0 - Authenticated (Editor+) Arbitrary File Read via Importer Source File
Medium 4.9
CWE-22Fixed in 1.4.0
- ID
- WPSEC-2026-0674
- Plugin
- Tainacan (tainacan)
- Affected
- all versions before 1.4.0
- Remediation
- Update to 1.4.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Weakness
- CWE-22
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- Tainacan on WPSec AttackSurface
- Fix released
- Published
Description
The Tainacan plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.3.0. The update handler of the importers REST endpoint called any importer setter named in the request body, including the one that sets the importer's source file path, and that path was not restricted to the uploads directory. This makes it possible for authenticated attackers with Tainacan management access, which the Editor role has by default, to read the contents of arbitrary files on the server, such as wp-config.php, through the importer's source preview and import.
References
- https://wpsec.com/vuln/WPSEC-2026-0674/
- https://plugins.svn.wordpress.org/tainacan/tags/1.4.0/
- https://wordpress.org/plugins/tainacan/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS