# Tainacan <= 1.3.0 - Authenticated (Editor+) Arbitrary File Read via Importer Source File

- **ID:** WPSEC-2026-0674
- **Plugin:** Tainacan (`tainacan`), https://wordpress.org/plugins/tainacan/
- **Affected versions:** all versions before 1.4.0
- **Fixed in:** 1.4.0 (Update to 1.4.0 or later.)
- **Severity:** Medium 4.9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
- **Weakness:** CWE-22
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/tainacan
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0674/

## Description

The Tainacan plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.3.0. The update handler of the importers REST endpoint called any importer setter named in the request body, including the one that sets the importer's source file path, and that path was not restricted to the uploads directory. This makes it possible for authenticated attackers with Tainacan management access, which the Editor role has by default, to read the contents of arbitrary files on the server, such as wp-config.php, through the importer's source preview and import.

## References

- https://wpsec.com/vuln/WPSEC-2026-0674/
- https://plugins.svn.wordpress.org/tainacan/tags/1.4.0/
- https://wordpress.org/plugins/tainacan/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0674/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
