{
 "id": "WPSEC-2026-0675",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0675/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0675/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0675/index.md",
 "title": "Tainacan <= 1.3.0 - Authenticated (Editor+) PHP Object Injection via Metadata Order and Type Options",
 "description": "The Tainacan plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.0. This is due to deserialization of untrusted input from stored metadata order fields and filter/metadata type option values, which are passed to unserialize() without restricting allowed classes. This makes it possible for authenticated attackers with collection or metadata editing privileges (Editor-level access and above) to inject a PHP object through the REST API. No POP chain is known in the plugin itself, but if one is present through another plugin or theme on the site, an attacker may be able to delete arbitrary files, retrieve sensitive data or execute code.",
 "plugin": {
  "slug": "tainacan",
  "name": "Tainacan",
  "full_name": "Tainacan",
  "wordpress_org": "https://wordpress.org/plugins/tainacan/",
  "advisories_url": "https://wpsec.com/vuln/plugin/tainacan/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/tainacan"
 },
 "type": "OBJECT INJECTION",
 "cwe": [
  "CWE-502"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.2,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.4.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.4.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.4.0",
 "remediation": "Update to 1.4.0 or later.",
 "fix_released": "2026-10-07T18:34:39+00:00",
 "published": "2026-10-08T18:42:43+00:00",
 "updated": "2026-10-08T07:41:04.537138+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0675/",
  "https://plugins.svn.wordpress.org/tainacan/tags/1.4.0/",
  "https://wordpress.org/plugins/tainacan/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/tainacan",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}