The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization checks in all versions up to, and including, 1.0.1. This is due to the `create_item_permissions_check()` function unconditionally returning true, which bypasses authentication and authorization validation. This makes it possible for unauthenticated attackers to create arbitrary metadata sections for any collection via the public REST API granted they can access the WordPress site.
Metrics
Affected Vendors & Products
References
History
Sun, 21 Dec 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization checks in all versions up to, and including, 1.0.1. This is due to the `create_item_permissions_check()` function unconditionally returning true, which bypasses authentication and authorization validation. This makes it possible for unauthenticated attackers to create arbitrary metadata sections for any collection via the public REST API granted they can access the WordPress site. | |
| Title | Tainacan <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Metadata Section Creation | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-12-21T02:20:32.422Z
Updated: 2025-12-21T02:20:32.422Z
Reserved: 2025-12-04T16:14:29.071Z
Link: CVE-2025-14043
No data.
Status : Received
Published: 2025-12-21T03:15:52.153
Modified: 2025-12-21T03:15:52.153
Link: CVE-2025-14043
No data.