Unauthorized Metadata Creation in Tainacan Plugin for WordPress
CVE-2025-14043
5.3MEDIUM
What is CVE-2025-14043?
The Tainacan plugin for WordPress contains a vulnerability that allows unauthorized users to create metadata sections due to inadequate authorization checks in its implementation. Specifically, the create_item_permissions_check() function lacks the necessary authentication and authorization validation, which allows attackers without valid credentials to exploit the public REST API and generate arbitrary metadata sections for collections. This oversight poses significant risks to the integrity of the data within the WordPress site.
Affected Version(s)
Tainacan * <= 1.0.1