Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 22 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Dec 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tainacan
Tainacan tainacan Wordpress Wordpress wordpress |
|
| Vendors & Products |
Tainacan
Tainacan tainacan Wordpress Wordpress wordpress |
Sun, 21 Dec 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Tainacan plugin for WordPress is vulnerable to unauthorized metadata section creation due to missing authorization checks in all versions up to, and including, 1.0.1. This is due to the `create_item_permissions_check()` function unconditionally returning true, which bypasses authentication and authorization validation. This makes it possible for unauthenticated attackers to create arbitrary metadata sections for any collection via the public REST API granted they can access the WordPress site. | |
| Title | Tainacan <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Metadata Section Creation | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-12-22T20:21:59.445Z
Reserved: 2025-12-04T16:14:29.071Z
Link: CVE-2025-14043
Updated: 2025-12-22T20:21:51.949Z
Status : Awaiting Analysis
Published: 2025-12-21T03:15:52.153
Modified: 2025-12-23T14:51:52.650
Link: CVE-2025-14043
No data.
OpenCVE Enrichment
Updated: 2025-12-22T11:40:19Z