{
 "id": "WPSEC-2026-0674",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0674/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0674/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0674/index.md",
 "title": "Tainacan <= 1.3.0 - Authenticated (Editor+) Arbitrary File Read via Importer Source File",
 "description": "The Tainacan plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.3.0. The update handler of the importers REST endpoint called any importer setter named in the request body, including the one that sets the importer's source file path, and that path was not restricted to the uploads directory. This makes it possible for authenticated attackers with Tainacan management access, which the Editor role has by default, to read the contents of arbitrary files on the server, such as wp-config.php, through the importer's source preview and import.",
 "plugin": {
  "slug": "tainacan",
  "name": "Tainacan",
  "full_name": "Tainacan",
  "wordpress_org": "https://wordpress.org/plugins/tainacan/",
  "advisories_url": "https://wpsec.com/vuln/plugin/tainacan/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/tainacan"
 },
 "type": "LFI",
 "cwe": [
  "CWE-22"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.9,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.4.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.4.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.4.0",
 "remediation": "Update to 1.4.0 or later.",
 "fix_released": "2026-10-07T18:34:39+00:00",
 "published": "2026-10-08T18:42:43+00:00",
 "updated": "2026-10-08T07:41:04.537138+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0674/",
  "https://plugins.svn.wordpress.org/tainacan/tags/1.4.0/",
  "https://wordpress.org/plugins/tainacan/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/tainacan",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}